From 505fcd9c3fda1f67b7b368a68a41b2df11e0920d Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Fri, 26 Sep 2025 05:17:02 -0500 Subject: [PATCH 01/68] update(blog)!: Add iOS vs Android Security: What Each Can Learn from the Other --- .../images/ios-vs-android/binarly-graphic.png | Bin 0 -> 80961 bytes blog/posts/ios-vs-android.md | 74 ++++++++++++++++++ 2 files changed, 74 insertions(+) create mode 100644 blog/assets/images/ios-vs-android/binarly-graphic.png create mode 100644 blog/posts/ios-vs-android.md diff --git a/blog/assets/images/ios-vs-android/binarly-graphic.png b/blog/assets/images/ios-vs-android/binarly-graphic.png new file mode 100644 index 0000000000000000000000000000000000000000..1cee1a019918330fc78fd8fc8d486f16f746c30a GIT binary patch literal 80961 zcmb5VWmuGL*EUQ_Nq2{|gmkAM-Koe>(lOFG;2=nMcXu};4ARowjdXX%J9u69b3Z=Y z_viaN+nncdthM&FuRMcPm1WRTNl;;6V9@1crPN_y;ALT8U^|dsK!2gY6x@M<`2r&+ zC86mC*asmc;%QB}{1CWbF24iqv5hZwAejARktbV=l#oDSeizLsM~n87G1FKa4@-)} zSZd0-4ZkK(0PWpCsIRf4FD$OZy$^VBPMfLUQvkzHDm=d$2c`sob< z9GFVULha30KgldrMm)20ua^YK2yhY@zGBV(|NQjr|MySUDdZ34<3E2|kQlh3rcGCh zv9jz+_XqzNL+?tnaJTPirY%RG4z%v#`8_v^w2ihT_I%I)Efi)AEX;3!+X3BoBkA3u*}`;xz3Lq0_64Z(PKmJ; zvowNT$#2KJ91^%@QYj97u>;oqYMNaAl}cV#+iGoYAyV0Ekx1Tzhd6IdNibUAt^7IS zEduDPsH8#Gu$vgF|4sMpYm_6UQlIy(gC5`|5D-jAcob7K+R{YMg6f< zQP#T}ItOs^ik0BU(^>wQ24xzOD-3+N3QjE+5 zlDLsWhpUEmqFe~m6HkjyeFjD0R4kdq>yX#m@oSgiJR3KXA4$uxr-QA#>vAxg=>xZg z&Z%#4Kz(=b8A}yn6X@GN8r!!1r5Co#bCq0oY0!3Bwa*AU+t;z-V7udzR`NN#6w0dgFx#Jp0yA5gN-idu(xm^U&!i%|Hb*X!a37zd;$~R z6k?wOu8}Q=j)Bz4e+{dQ#L;L-(^|CuMD{i6qWo zL_8xCxUf|E`)OO_+?F2cbJiQ&=UdNx`ajlWt`dd?uDtnmj3P>d+A>$D8ldk_R2X)# zuTiWqraI0eHYD zu?QzI*W8l_H;MmiQm#83pulL)wl#KA`^N&Pfi_8MZfJrd+TfrT`XzB3;L0q8M`h!* z;feO9t*83i_}7j?$@tz*rE~n-m!KYLoLeGLnCRAxU;D?b=chSqPX2njy3>^wiy2>m zU_jypaP!TzVRpulL_P%TA2cpIc>vkn4t@fhi$a20xY+PsgUP`Y4q>{pWl&u4}i%nOx)PC5* zZ@NA0u{f;t+^&U8t8c+?3GT`=j23L`omb6nH6k?<3b&~0&OalsX-M&J-81$Orb|}v zq0Z3n9mO5UjH4k5j%~sT@dy~8CFPw_<`twbNKx88d~y+=uW1rT)>{;}U=N<*Icx2O|NY0XDZelK6stHI&Tlr6Yd%*Ke`$dI`Wa;n}WzZK|mtjM*)2RL z)NMB3g5aX8F?2{^kFDwIaC)bv0^*9ChbeZG%$DXXR(C$^w5}5SzsytyHPgVR0%-ma%B8-w;Mi$PhPQzcJ0^#@b(pPh=OH&tG|EeEduUA_ zZNIre6Y_%jlcr2TS#C2Incumc*X0+(E0TJ4zi)|UgVP9wPH832S#M|d9T(si(9*RT zOKr{0^5nMYw;VxI(*p*3vJ80L#`%Ch-1&uxHQN>M+5)MX_BIn*0myrqE^BFrQJ))U(XH)7=E@)&s)-eU-j;tb= z+jqQCwHN)1+}7>PGIMT05NXO3P`Kw8&$e+?|GGh&R_;|SFssd8_br4q?6L zvU94;v@#0uP5Pb8o2Wl6#-fVPX zN1n)bF3TT@W=P+8R&ZC(UZCz=Xxu#JY^WsyvY_>Q60WKyV7`+UlA`}9&dim`K*ePpMMv=oUj!}$V#G#Ue#xHm{FDE4o??PGSC=RfQyW< z^!Z+&{+Er?#IW!UeeqJY0$Nzlbc@W_h!2~xG1i@9O=SiL;mEWs@TvU!yfRI0iDlk| zs3siq^*0ygN49WszTC($rt~&R5pBL6FMfy@7k_gbWl5|86ZZ?I^8vW|nq|sJ6<=>| zA;L-6Jj*%I34;^zHUjbuqK^7IelI;|X>d=QXc=P5R!}x?B{jxi;9bz#)j8f}%zLZP z7#c8JKUk*c5-5(7@1Im@3e6^Vi50<4QeTUyHw6Nd2p)-rO3wyK2THkzO(@kY1kwpK z_KtsiZ$R!pYv0hBjx{=vC}t|L%q+IFkjr2*f7|a{ti?(?KxC8FkU5?i?z{6_tv;>? zPrpg&Bo-eaA6UIm-eGM?%}%+q*avJn+6U>~mY8LEBdfel)A%lk=WJICoWI7*t2Ujp}VRpcc^|@MAsW&{ZAAQlf$# zlr;Wn4|wo_<)aV5dLfI8gFAFawTm9d)G^j)eI$fvlt*l%=6KZ z{k4OzI)(`kAs0vAvLWl+mq86AYD6U;!BiBDGwPC1g&J3z8qzxpe75t0B1dR!9d5L| zf5?-ny-fx{E)bx)))D^wTN9;6)T7U9XC=&q9~?B1E|13{1fb>tivg!rH2+>s^7^39 zi@o0KacH^N4;7BNK>-Y|`fL33r3Q)ttd7w95_*3HDyFFF)C@jif6D{36OC1Q_jn#lO`3ZM_B%jAK6!{OD@H+C&WsMDS-b%n}BICShn3YNj zg6&-Y+4p+;EKN+x?QymjiT4-n53Zm{G{$LYVD_W7lL>~Grm;tw#8Kp*`E%H(tVp;CTTQr$D43U^yvLfwLpamshdcW8FRgW!%yet8P(mRyrZEi10t+mj&R_(f?gT^?PkK1Vf6oV)~aIBZ$C{{3TW zJ+5J;{`8>SC&M%4XMuvehv_+ByVqkKPa{bx^jK)hlK4hj80>7{FlRB?uKzfkNkyFVB(@q~&~_XcCnCDgsF#`s@2k51VPSw^Vf&Z$JVS<7qUJ2tjR@ zZ-Y1%;gQ>2O_&xZu&Kcl2btfU9%Co5DRkWZU#Vo5+Je`+6wH??<(|6ADap5TI2Iq$ zZ9P!nS!&iSTik~GE`)!iYo0mTb#~6%`r0U$Q^(^V&iM?Jvooy2p6rHvYU>~7)~Hen zT(J0}8${>zT|9W|s`04m_AZUDUhtGop%#%ByFwqervHDWNrXeeo-So{%x~x>upcrZ z*5`IZrS<8|seYAy#A3g?X3sWMP2+uq*Iy z`@Y(*OAzPmLfAFjV5!Vreg7GkjUbU>K%2mq{TYYW6qsp_Q@^!D=iWQon9<=z3XKpR zf1zfb8)*-8VZfq=>v)VdZh8?Z%F33fl;R2vD_$}!7_GDp_lZ*pqqq@1SgV~`Je1mH zB%lJpOVKjDI|`B8Uq3L)zu!40i&(~m`RaX6bM5Hq7^zsBi&r-{xTnWh)U6O*xI+ z-PYa@ZM};Pb2m~%t!Ct+b38a=1U5mm`>z3aO|20^*RJjd_mE(cY@xd}2n z9B`e5*4t%oKOu~rmSlwIJ~_?X_1st}>a=dbEymZ|ch*Gsse~#Sj`cJ28PsO40=xboME$^N}?Q+a_h*XlD-isR|mO}GD`bZcJyyH9< zYFI5TTM|viP`4Rar{ja@Gk)u?Gf@12zgq1uOeU(iRT3?D32D>%L~I3jwcg8pW$m zb>Vhm4|T@O=UW@{ZqA{l&Rv7pe0bUW3y<6ZKg8&!p#+0R+UUoPiwyp8DI-BBF188k zY!=~3$rUozPH0YoIFK@AWl~u5WZzLGofp5NXiGp|oHGL#403asreLLw`bF36htI>( zFU15b?I!W*xBo&tH=JejMpA1?!suBLHponH?O*Wp2Yq1ds5Nz?w|}@MpKgEhuJq$h zjuf9?+?5us*zhG#E7t?m&RR1WabB#FL?MAbEh)Ht7<7uqdiNpsZPK15pu!=C1Gjzv z+B2atGHhRNYTIAaWO&?RMv^suZzn!`5)aJV=t1vm{fm(35?xfK{lJKyG_H9W4Sk??sP-4X%K1+Jo-?)%UQM0S%J!AZ$4YH`v0ogr#wSIYVfRQ#`+>ckU?OA#{ zN|{-w8PiG|)TKDX2~EGDt&Pa9E0{-8NxLu(gV{ZG;%+9t3By4mhRtv&6zR(Q=*N92 z2BE1wz;PEVa$yF^5`M{max$sj`Asq+0f(SVAaQ2yO>EXCBQlj6_v-Rd# zj%$<5Y-i25v+&Rwfp*5!5x9cGda87?H+z zYt^z*Rx)XH7lGPXF$x&hRk2(qn%>>?&RbYLVKl&w2DwKP&~h!U{wMSQpGHo$qA84} zz8ePUx_9~m)kpWDyUc`O@eft^{=aVA5Y;EQeWZsD?pFx~i)ZsZDx!J=4n1E-n;mo< zZF>bF=b8wyWwX0J63N{iA{l%S?yykITXyufYa<@$jh#>NsR$z4rjIJ&0(rr%xjrX;mmOki#s;>L2Gj_dBP-z3(8atgf;dw=SG^j<;_(I#p#;d3J|}6c zeW|^31hP5?kBMavU9W?%VJCemhaN5H*wy>h)sy*E5LXT@M`-E)?wAY~*_ zi{Td{&MECF_D3nx+A#*2a+ZAcjJV~!qqbdK?^Lu`=V~;zL(i4cOy@0gwqWm0t+HP< zv_JUzxoCvK%6;{Q^#g75`4~ZuKu8^H&Fl?=)MuYmZY$8gFm}xqP^^m}Q1K zqOMu8Ea)TF$x}+_nO_FiRUzGvTFyT_ii@$T*3+03Y<6OegS^X=d?@5;KoR{>mG2LO z#=(9%D_FM3`uxF6p4^aeTeyAvm7hv0#|>RmDQ2;4!{0Yl0>mBA#$XaHE0Y${y~ehr{}o1Y zp8g8;^YQQdCjw5oSYs5-pLnufKvkCf{;%uw%-N&oFyDh}b=N7fbl0cxl&DsL(;jTP zt5e`l{!#x>nbPMrH9{tuB8+Tk5xs+ro{tWjBJZ|e3kxE?B^ZC{HNWxB8xT4FhwJ)a zPB+R`GvQc-es8f*7$kXvYqzrlY)wC`wzOe{ZH^#O9t5U(-fTpWZ-fgUzG$-U^4Kkv zigJFbfH26(3U<=0aX%lOQl&zTK@*N&>FS4?Zr%x3B&glic#r<`0{!R2)KlQN+aF5N3Vd3m8UuXS<1^od7tsFdGfPyoQvyK8kOnfS`0m$q^?|@0 zEZLkFOBT4Vb$2hz1${KG^`rs|&C{RO`xnngK%_f|KCSY=mIu@I>lhU;)f(46u~(-e z3?n$QJubSk22Yx2Eji>ru102JfG!`+v!R4oqePKPO>9`**}s8nLY3ZYPWqRh^cksy#B%z`O}T2 z5h43Bo@mM*w=p|Lg(Y-{-Hyyx3?1$U5E!HK_bO|;%3Ipty ziCh7>EK))MmmGP~MPDubSpJ;4br0<+d!S^-nL|@Bnym$dv2W-Zs!#Q3WYY;RHFmCS z#*~nCDZNAAH3YHxyd7ZZ7N@}lG~7e0LdB{4mn~W<+Y3Lxs(rD0z`G*dWrqJ1Kp7C94yu3f-1Yt?9ezgO$;1=2_wn5JI|0aH`h>|;WH_hS>fAj`n?2htq1dLPaD1y-vIaTWYcG@=Y``t1R zT#>qxI+X)25d9#AGw9*%wfH_qnN|EI7|Xqep*(vl{f?1lohp(S@<2Dpf2M4u$Jrk* ziVuxgv$-i2f##M`dcS~&(rdUTKdsj`-!dNu5Z_||-7EB9Xy31nuh745ygJiL z>z6f$iGKeJt`~Zyx+CsYeihKR(ZaZ*#x3&2t}u z!!H9OcASbus^)-TgA&hq^Ka!U*l>CD5jAB>A?8OV6_XXi{*R2LhD9cm`({usu^R}<;c@ACX~6x~7u&z>-wSsBqTx2v*nvlCQDKkae0;tFmpcj9=g!voB1_Z;+LWBIAENTp zD6JmJ2}TQ;~TEOcb!;w#pSn)kzjAyP|>0?QvYVX-VZB)i!D3a8Kvib|1m!)*w(?` z9B!Jtgi?Yn@)}22`8+Sh_CugfXF&`Wexvpq?YnWgbAK%$3+Zpg{K29L!Vn91De6ap zHCs&ce>!qo@C)&?LE@)h5{Qi8-YQj_ms$hfIBKEMtJWHVr{TA3cC6!riQ$+ABF#Gv z4-%_#b|Am6F05jR!AeJ2mTw$gp8K)Iha2yRqk8Mj@80VP&p!{;QcV3nBd%zl{K(DaB!GJ64u+Y^1ZbX5q%6d8T zj?$Uvs!6Nu{8u_%jh%jk^|Cgr)Li9tb+}f}!(4xUxylyTz7!UD^YR}K+p$uuMHrhF z!$v=-8Hmbf<4RN5<$p#aHZH#67bSX5Cdm)!%U-WSd$Gi}E-&Xo>~01xvsk>BLZ)(A zmTrIJ%bo=4KZ6qR5c#WR9gc}Y4KdqbQ5ZAGFP~tOP@~F}{gi{Bk_wIqwlN4B zw17pl`R#FJy}tX)0Elf6)y$Y!k5OgD8n#mI2P^*<0fC-qR?tA6(x9Zm`ZHtSNPbn!qM~Hi6hRNaFe3N4;&=b8TFn`EdE(sED3EaI2eUu zoR-Z`h|$u49Jl}lh~LfdKP|r@q(E_b7yz!VhN12fw)l}r5RvNSi#>j<(^9`-V&nGn z+Qc2$24Oo}V+!hfJI=Kr2c=<}4&sfOx!?5Ps9-|R3j?OhhU-`gKZKp+gJIe)Y*2wm|bQ^$77kVQ` z14tDPSShNQScE~9kfDQX0o%M6jxN|orlLa_2;^O~KMN7erYPT-d!7C{SB_BQ06Lt~ zP@LqYj;7jgzTD}g5tX%~Q3E4L#u~|)bGrNAbZFYnhIzgGM?gDcDM~*2r*{rvfv{B% zuXureKg7pk%y8}87v?$>2HZzkMF>&fdFXi>qXZVdyz*y?9C(~CC7#};vx4?xKns&! z0j4K=E-j)75Z=|Ph*6~jQ^W_$}vv9!1bA3rgXBbNzPKAIKUg@!~SFO_e z7^!=*DIxo{Pd9=;JKq)$Zt_6KO;b8%^Ss!BKcz~k;3cyN|D=QevBLUG6xucHp=83; znxBH^O6QAncuG=@ZMMch>alJ&1aS%p_iR%@pcBM(>=a? z6R9Cgk^5@<3%VPOZ&xtPm+88llqa^*94j7)SO`h5sEaWD0lr9gLy z3Ui)po@IG8+oITht2Fa^f2!7GhUYIy(v4}k;EG6Sdg=@ECA4^?zO;~C@xtn+Po{!u zdQk6dmDk3ZB5Afr26Tt6;EjM`@4Y$UP*(bfR8_)c!Y-2Jr#aVK99Un|(x#bqHHpd; zIwp7{hH_)rcOXVj0zc9Qlowc0xAMUO6CV;@jz82l?hXj;oRN$1O9gbXyFAD~FDFd1 zdPf(>8j{SobJV>~+hAk>7-LRU9T1Mjj_ZtMhfw4T*?EA|-8bLPHQ6@g9O^FAx-$$4 zU5P%dz6YoXCKd6eNE!(?Ru&Q-usnqgicUipsaoKFlUs60U`XZtw)AV)^=oOjQxf{7 z-vM!-lls-O;`IeNmkd6G8@`NmfbB)tCluJ2OU-^+0_~QM{JHR>AkJ}M$Z8z1*TkgL zaPhQdiaNu`(g}j)iY1ALk5?>VA~$AM8cyXoX?4AdEwgy2<85H@Xl?zuVG76_x~fDDskzhXPEZ!U94x{>=V1B^_|-P zt7quO;L#uB>j6VfShJS~+4E4|+T|#iEh+GQyop^x^MgSH+T5p#-ma6j;0?{0_+=Oz z-m8&6B`g#y$YXjf<_te77Ip>~t_+HIZ$|awY@1 z#W-n}qc`z144jGhKu7#jnz0nUUDT+cQfJ)TXt>fkT~zI#d_xYpO-K&iCR8)Kv$Y4A z&@bDd`tPg-fz@iu&&5;H9!uSPg^x;~&07 z&+C-7>`!Tf+G5a+Mhtp&CSyS2S3mvdJLE66hyS?)!~eO%pO;YIo`T0ZI4_@J%no5+`N1%sh zJ;ih9EN)!NZ8dDPj(P69VTv>V`X^S|1zM)&UU*{lxCt6L zwR`svU}Qh9ezFg^a1i_JcbIkcvkbg2a;+4bp(d1Zt8cd(*1Sv^stWnX$N$A%k?Imb zLBi;gjf3%N(8w}n>;t7p{);|N|N?uH^Ktjf2 zPLmtP%b7e!8fH8XY?l|FUl-dRud4QBdeKJnNnogrkc*h z?q2Ss=2XnTMIOH?RT+9jAoPg-@<%!Dib70Vb-45p+Iz}$a|CCJ*msH_xo*&Tj2`Ir zQ7;jNzP7X-F6?8wph7w8lvADV9}@Y`5qZ!f!cLlJ@3ZeC&b?=sagUiF(kP%iylm`( z>OP9~dCTuBMwGE-cg$6uq(pW)Yrw7Iu-IwX)cdO(T|JQngc!L{Vk~ksY<}$4v33U_ z<5KM-y1?Io$=lKmbt>6sl8DhKXyPZ^{`d{ROz>}zIYBkaFeJ5P15lfYd50J)lAIFEN_m^MK zs~~y5*Kj~6V=2#sCJf`JYvGbcAN^W>+8K&fzM8?^@7sHi0>x&#DA%e$_5Zno+7f{$ zmp+hp{Y)_LCk6WOxlijO^~U({(X$4>dH&OhSjRtrd&kZ@aYmw zic{uAwS{lpgy}SQ9qoAF*!S&b*b|6w`8JM=xe{8qBA38n_!UyC z<1g)(&!ona+5)Axc8H;QCEpDBKD$08I4t0wGzte9!5!)GcnD#`*4|jLCq*gu2(?1} z_+|3su`X+Mr5C$)>r*a0W=7mo5-&G%@ic%ATehy>1yN(C^Cx5Sc%|6l#|7|IJcS~3 z|8fMn3z-GoH5_e|Ux?pD^#}Yfd;ABOjjU$Lf1gYXJ=w`@caXkW{sGQpr*wtt!-old z_UXHF`+Gp1i~?r%jdY7MR?zL577jR8#Mp--n^iJ3W4baUe7mu<@%5tWLT}Z_I#FD} z4QBtN+1-ytwMV@NOPKU}QJhP-AK-_d;f5-euV)AwzR%JAz8ak0P@=M zb&7;VE5-^oeDW{Cf-R)wNJ(_utfm-s}zvyFtfNjE6%gkZsVUBKr9)xWl1H@|ZObVQc>VUFZ=m zx%itHH$>0bIy8|u#kgN(Ej8e7kq?XxFcs44d%_tn@!R;q1IVlYU@@8hv!8n}PFx+X z!DMuH;_7FO#pfC>3#q*~e8kzZP{?mrfg>5$QNmqeM9E_>G_K~NZvsK1b$jrLSIOnDeKCHY<2i0y zP@i)r!<$#o&6kxxpD=P;6LPL{PuXKnu@gygb2@6RI~~|MIY~EY>l2ZY@DxRWf8mfj zNYFKu`lro<@I1N^Iu2-1MXpfid!i*F6V~^PJ7luVPdNN+-&xcmZ|XDEzI(Y=FF4_* zf5E&_B5t)&F$UZyuep#~7QB_WsFdp^=mdYeJz=?Lo&W@Cc}RXkAQi%%F<9JQ;jcynN*V z{)Dv!(YY5tq3%K}8kmkszIp8IALdyf|592fz5iNq=`Fhj_-QbYY{CaFud!a z1}P4hX8lDru{^#!xx8|-541}Wbiq*3BgGObY5i5OmG}Hr27;VKQ0nsdBgB{od#{vV z`UIPYdi%<6*vzo~y?7s_Q5=%8SBVH&TQoSp2(7Egy}o>ed?a-J@M$=wKCk`tq-Y ze@|!n>IE?vmw-Hlxy6y(#WO)`3L# z7)xM2PzY|Ys2GE42jIdRi3tx$mZiw0kDX?;b4{{1RP_ohKUPw+f&PIq>TZmVYxq{ur(oQAGqu3yw91=8-pc;yWVl8{;Yf7Q0g@;<}-5T z4G8X}-vJ4#dx)`noXeh*k{2d3Akwx%U7zxJ5`jxrr`Y@B{@noY_m?ekJ_ZlXiVrpl z3Ac{}XYb(0_Pnz083S53o)o7`cDLLScMy5b9<(3QLhBw_c}^Zmy`SYptm1-Ioz6&j zmKSS+BvHq*cr9o53J6_Sll!4#>9dR__*177x^=aC`bDMR%SRozZ`BIt1|vn&IQk|z zSyx%rlH}AY2c?jJX?4bGeHs9r)Sgv@sdV$bVkR5rwbhtz z7JbAO(_=e*EU>tD)1s-pfpXYHQi=bmypM5A6Ia)J39fH+!=HB{)i|b? zHJHmH>nKAQGeDj%Op^4lE#%rAmr*5wlzF)n^I}-i(~UynR(u0Ojpq?%_}IcS>;(Nh z;vlrLL3TEJjdb@ajYZ`bApZI=S9%wChq`<;*euvO^IkcpT=ZYnFg>HqYRoC~=<~%H z?ZcGNy4Kp-uiOnS50yM0@e|<-&mW3zal5-;D(FMvg7;=<9r*N%Ze4>aI8=tS#^M>h zZPq~v1*_uUo4mGMfg|Da>3~Sl!d9@x#PUz&`DMB9N7{ZcTbAP}3)9CBVV35#KN~6p zUBQBnJPJqMO3aHVX5MJV=HEk_ZkzF-$^lcEXSK+Of%5Q9nU!>6AkM+d-;rr!j+sG5 zZgDS0B@XY%qb2moj&~fEDJN+im<4izS_A!2r(0Y`?Pk3FfT57gYs`f`L!=cTOO3{bk{{T}!##^u>Z1$NEnHCyDJ?SJavc0J(h zRQCRMwL0aGI6@lTsW?TPI62()5^LwPAh^^1-niLLYJ2CB7K$wfv zHx;2({}glp%nmwImL6^~DWbs^8qYSXI^u}G#E2_@<=-54SK`$%F${d4Y;Pv;j3nIu zUd=ar$kaWq541Qj%*?au$-?3XB@*IOW}eFy@tJ_p8CPcV{nzUoJztynS4!lJ4Z6^6 z)&jQ;;N3n@v4o~;ZyBhGrBPnL8`Cg2GD5??B|<8-r88oh7|VLZm^y_%qyC}UHI+c3iV@8bp1=R&ID|LJkkk- z$~kGWq|y`Ubrvi5_2Ndqc?j_NcxIKOU*9S{;4DiycxDk^cR>ar;Fpww(#^F$AMD*j!5C9FkjWiC%eZl%!Bc?F&iFrGYdeBZ?9 zM)HiIfTqiTF~p8_!W?%)!c;Y(qy$qk@#*-a5^D{v=-b9z$+>`kvpgRTZyhDc-S22; z+n)udkk&E$+ni*xUmKJYRRRD{u5Eb(mF6Pz^>pwxBF<%grs#xT%oE`v+oUKI+=8)6 zSL$A0XCFXNpP@?UC6}ETs@zvf`@!2z2VqWs@zXwKk@cjdcU%`ss9$8F?q8L-BMA;& zS@WRW|G<$OtX%=?6v>eR=n%Y-TWkY#EaUqOz!9^jr{E^um69NfqGYNio0Ly%m!NF= zWb@-%0!BQK8!Xacu_!c%j3C(}xBlVN>o}2kye&)m5vp#yMW2 zk87S<gLa{{N=OXla9+W^N(y2kV2cdEJ2 zn3s=GU?tbS)~&T)>r3=^Sk3Z&4JS%od|q=`_dfs`*F{@jT8&8X zJFM3e@e~VA-Z@&KTS?9Wl!z#eaJv~Ms@Q~WxpP?}H9<{)JHIRJ+K2-DTntHBPq$D- zPrEfwl61OfAmyZyXP)Zko`U)gl!8)C+&nOVEOmiwx>k zh|q=iKS7)$5s(L*zaTm{t*GJkny=?N5LubV0Dr<&P`b>@zbr6wN@M32c#_#get0BaN;Wk8Yu^Lv6{etvaGeIp95M@jG4?wiS#FPAl3uJ+de| zqD2LH_SaTX#x5@A_3<-P*dsif2ZP72I>$olwP8j0sO69M3`+rE2rvx0)od}Ooxy0-Jsdu13n*s)q=Q`wO z`P9%2Y1nvJ-LtTMazD47SB9pK7+-aYL~Qq*>9sHc(m=(TrkgHH&ECC2CE8mM341P0 zq;RWBO(&lLL?woJ#Z#t_P3MgeD5MYcYMaX7t<{>fZ{+gr+uksc{>1Ro?##*VRa@}G zHjDu_I~NJ`YNqgCwVKMJgcZCz@iQhQ&5MqJ(9twhF%`c*N3V4t1Lc=(1sY{hoh z%_MyZjS1?x5#___J^^+KR+K92$1mb;9(_$6`tk{0&o==cn)U6q+*(I*gV}LJvF1Ck zqHb?k8wML^Ivdnca^V23+_WahCDJ%~n^6O4?@(XOxaD@qN3IB1Zw?E-)y>FLx zb@IJcfZ_8}N0>gbqU10Y>ZXbn(QCuO8BC%DZfVI*7>Z77Nf?FyhO6u3HJJ3NKX+4U z6y*||8&4>}mkLebcdo2RZeT*OCMBI!rv`F4ebf zALoOu3qSfa)<5UA@zZfAg(z!}!LMgJPlQB>!%p;x(Rxv7V=2?my?ah8GV>tx!Yx$1 zg;5o%v%~moF7bjX*N-JqUIG6Q z$$oK7o(1-1w@tiVRPHZ1?@}|@8Hc?SuAom6ojtSnm9V8`+=j6b_!=rSul<=D zf~WD>ajLjb{m*&FJNq*R1)bj;n+u@*$HU?MTI43{C46=~q5MSYAN`gcdfWKbE>8I+;bAx!eTz*P@lNd)hPwHm)2B?LLacO<_+u;X&d04&n(s zHep=LN38l+c6z<1Mt(?J&UC(R2a4pRJ!72;1>!hD{qLaz%jcXglR^UXUY;>YZTI{! z(hMS2Bxh#AGrOPXJ){;hW6o$_F=oGW$xKa?n9MSyejltv)4({C=@0Qa6{g3*m;EOj z9tgNKrz6QyT=A=p8S;y06+B=fK2&dhLjg4A?zA>XpsxGHCu9Uz6`IzDB0(AY(cvE? z_#(&J+=dO7;05y%Sevv!)7}tC%A3@5=c5kf{vKFl$*mpLAi|%4$9&I z|FSp&#+!<Y%3@cD-<^2IL8#s0u#8HpfFzeenJfTr;mp@w5#J@14m8od4RoS7i+Rx1QZqt^b_3rq6bXgL#D|$`557vE~I$ zY8U!{i5a^353OL@AU>g)%D>#CYO;uRo#O=fSUXiy8%9F6D7uj<~eKYU%IYrRBrJTJB1_sV` z#2#Ysx=L7gw#|i5FGzadRVXeY2_rBKQl;0KkSr64L-+b?ScWsWJf&Apf<>eKjKoLT@bE+1h_<<|9 zlJE2#;ay;tkow|00lKmI1?e+=N-Skbx4p!Heyuwk?7QO>>m!_oP4@0A_;#de41TBN zbonHxEX)(%mG2SXmTf*Eot3q~R9fG{;@HXRAmfm6*;t{=1e4;eLd3y4QgghK2(-&p z+~M3n2UUtb=^N;h1*;1zjX^R@d;hJ}$DyUhEY{F(P&|ED>|SgLQ_ zK0WHgn}$UsZBCdj+d$BeGrn8PEJscf%qYwoHH^Nu-<#QtHr*6gSei<5^ExP+uS0RhdXT#L z`+D)ZhO+?>SfVOF)7r=nu~RG|Nr|{gN2`&Nok61#Q5NGB?1ThV|4GX+O^iInscsMZA_<{p$pN#lFS#!eav;$i*7kM^-<)=K|isPyTu_Hh(zXPzMgZUHg8%zwt`I=W@> zEb6^vz;5Y?(N3O9*<|9vj?nOD6pkKyglZPI^vxPJ908oaLOo`@U7;A7lnnL|>ciXcY$=&v%IZ3j+j$ z22}>&ff$&Wj-|pvtyQWx{8N^(6pCacXs7MtLOo2UKR1GyvLLKOqfd4b%@jATcYb3D z-0X=QmJ>Y~2_iW_ewp$iefnKud>yK25Wk1+y5aKXLh35)YU~>9n&;Z>y5aiPs%Vk* z-&5(CwOZ9c0ac43B=RL@|M=TJM<;oQTr$xfZNJc~tB19#{gdn*pa)vB(jk}TFCw(E zsF{iWxInn4z2vmkZwbG9zr!>)wm>2p{1qGrjt8UihX}e54&(gy0=S7J?`JtTp=b_R=&p7mQPgr?({Tb=@21}jfh0Ygiv zw=|Ep^AwQ2!~-pL_sndu`Vvr)bI)b+82KN{W-{bFOqJ&#+y{;+6)>E*hr|T84s{Ws zIp@C^lL#@>AWWkYA%H6f15Y@!vk#SEN*(0Ty;#LTQNw*r3nMk_9ydZ{Nl{1w`bvb0 zxAP~NuAO0;>n~QcLiO_*v$wHal>I~L^MYS1c?aTOjua`svH7NY6`4if9TQwI+A5-^ zl2jHgT)96=t+K3guL`e9uPU!pHATtsRvSf=QdXIjOd5?XMdyjv=a;u{k z9@tTI3Ik!7wk+o%J%|63#KA&5Ayur!NbMJ#EB|~ZH&qpmd{xF;`wcrAZ~%cAiUk=T zPmc3WZL}HtFhhpVOMkt&`=H#;RQ?j4eW6x7dX9W)C_@a5OCuj6-G1E`+6mg}+IekX zf`t&R$;iqW|7+;f_Y5ypEulhm;Pxu(L8|rnVAWSR;z2_Bj!n)`?ct9To01AT-E?o1 zhQ_P(1vci3@}YZbmqb^xtRSAh{C~~+xr&7Z8h~*1ifJ0I0%UM7O&nT= zaw(bDRo-?=;HC!pl0948bG3DXqyH5vJGEF`Wt|sI_$4pe1#?mW~HCpu@e#>!r zu{@*{+b>uKXY}&YkTBed>&6TpTL3ow<3g#lNIE!Nu!q@%G@zCE6dv^b&-H}HKd5Zy z0`4msxBNH8HX+s!BV@1Q1jJ7i6xQ|I{=Htees%AwQMK%PZ+>jY_A2q6t@MJLZl|N! zoDe`oJDP?*{*x=@SXNn(J(da8xQ$N-%D}q|WyV@Hfq^KC1#X7I&kh_KA?F;@|Be8fm)|2Z<6`K& zv8byuQt}qv)F3z~l^lAYRXKnTM{bJE1i{WWXdha`^jdDShermmndRcI}@#t-8oXxX&^%nT@^YdUXLRi;?FDB(mzz{fBgK z1Ld&SMu~|lJuEe9^ z&QuVEd+?wCh=1VTjb5u5^9k`}p?EpD2^q2nGZC*{s}1p*f)Mxto$0;ef3wlbc~1Y_ zir{Te%YFTU2$~<=Ci}Ag0H<0OI@XbMuEiRG^Fc{PjIK?kPl&cSIRvH8U?0Km+hc$& zWz?o@R+s@0`{*SP zm3!R7`5(O~7!YLyl-403D-;@vnU*d!nGh&`66i%|V$|Ip7fKagGg?jcgBzS3|4n>L zLVY99q0qW5NU-$A#}p4S1>)$uy`@pSqS_-dWvL^a#YAWi4fGtlWK;Y{cr93yoRCUa zy_Y^xSsSX@c=Tlp0`;V~1=MDYHG)Uex&Z(1k?$%vn0UOJu= zJgjByJ3o#H+$%oT9#s}P0i_Vw*Hf2iQs;Ako-sHwXi_KV8|A@YXzB0a{Q+w|K??qQ z`hKj)AHRAPEB~_;8yfSD34f_UCX#>YllL`4A6<=nl%6#Ntn-3z z!#+(vzN*`X2DjkoN9%YO1~cYV22nt-Q@z=8u()7UqaZPKeMNZ-7FdkKfmND$(QNI=5i@nHj}2yHVmK}lei(sO;)74R#SDrPL5!u6Xd}cBSes5= z-i62pB|9Y0L|HzGHhA861v*?O>Ql;}S+p8Dp+huApB)`yG42m6eMtXV15Yr?qwBco zNK9csEO^S^a0xSgyS&t2m=UuT-aqf`OgR6P?zJE&3&%>`aV>!9(pm)6Ad=Lkt;B&6 zT#A>9VP@oemAH~TBw4}E(-C)B@DrC}MQTxX!|?skwu-~(Kz_70w?z-k+@jHmPHluj zVszE;ol7#^p}N!aoQ39NYHyj*Q8cTlI>N;STW$W);G+JJoBy8Yh;sp2RvrJKR5S8Xl7KMY7iOMcm9)}bKGzHEcGoOVPC-ww7maY%o z#TlY@giHwDD79Jd`E@o_4He+>&RB%PPlQm*Z*VCw^Stj6ZzsGEUl|EjCQUh$CnUt4 zij9*y{5kXfmdeXg7Phna)j87YgEo$~MSyxIuA-|&AC_GGoN{&)Pv1BGcmCfK)6!^v z81_LVRHcGjV10FvX-(#X4GraJ3Gid9arXWzVLzE zg)E3HvCd%vLyV?Hr4NHYni8Jc=eq<|Ny6c1()${Bq68^OutXu<5q{z4{a-_$uhZ_O zI_o`BM_b1HZfn*vC{&_D8sFF=6;nF;o_0B&T#lsg>&-9!M_S(al9X3`;4crhMxkAW zN}JE2%Np5Ij(Rzw*ii|k^I+xt)QBr-eEV4t$1z)hpl8l>HUr#!q1ImG?Av3H141#$ zYYayfL_3y$DDx7RVH@$@wh%+WJS@yc!i5eQ38hRujM5{#?iKJ8D2?E|d$gM;cJ@5G z{S-M3(ZMwhGx{X+4bIMeAooG@ff5_~*n?K9B8KMzPi<7g>MB;88JP1&h-DGAnSK#p zIqlyEV)~(}28h!GC4mAVG?z1L{kObHX<+jSwgseFoay6F!(NUTWUA-g1GaH@=&)@J z*-MI?J>eWKm`{#Fv`@U}!) zYkK1SN$g27m%*3o!qMm`{9O-c=(6vzs(dF#T0J2aRaGFpEyq6`M?c;}OxsGHtatVc z8FGr;rAaGsYQi-~#f&1Er61dgR5X!Ks0fTj-McMz%fsp<4jwpD3#RJ&a10PtVCM-~ zrJ)_BlSGVvi+8)nO)7UHcBzj3@47-A@>kcc{)6=@ypMn`YMNc1#kx+|q{UIJ^4 zH?eSq{7f7l;V9(r}JN)ZDM<4i}@`zmZEbEwbzUs z$Qqn;ca;st))0@S>_-F*k|_=wJq`r@;OaA8kX&n~6j046LiFEmEV zg$}v_T#XfYN`^E|^#}#$xWr;>llGPI%_X20u<8n^zx)op=#H(u=`2zey#BsoHX}uk z&XdTe;eMudh920p5ChywHy7WgOEmncmzFLI+2}kQHkg0{J&wNm6CK$7H6fYd2XLnC zVIcBxpx$aZ0~pc>=ntV z-B}a?Kq4bT&tMA1@=7ie9DW7Y?K`w-64@Q1aJ8Gzj4BZ=k_-xjb#i^7xzwpU$ckAf zTOIT><2PajOQ-u2?F!Fw_T>y;z0Tf7S&f@J<9OvO!GaErCSluENZ(+jiDT+4P53-7 z+%bqb+anB#41MT4g^KKL@C}ETG^TwpJbAVij)8tyo=*JV81xfLK~Xu9j-b5qdpb{n z3RF+LsRTXF+(V|2XV4DQ3%lkEx!I)p_!T~|$p^=i--VeN(sT|idlZ29YX}hcR*M%c z72I|>;5IR5%My?5t7vN~)t2I_J8LTC;iMhsNmst@v}pTkwfn5hh#DAYMINXfys+fw zRuZRM+&c>9#oKb`#S3g>tkrypJUDEKfv4I%T6_@r%P6w4d&(K|3xX)BFIrqHuEgw8 zHN_{mKZ+y|)-LF(xYFZ>e@HULf2ZqPCr6rR<7MXwIihFl?f1_D5VQ7n8>Wn&U=2!F zO_KVPU9lej|6qMrE9+@-q}lrwwqV$Pt`Dc6M2*m8)xI?uM||)X!;62uoy@@DBGrQ4 z7fa>}F^I2~4=crJ8>q@|nQhlmC(7>!wT_h^5*?|n_+C_+pJ^-3jYNaWf>Vm~-p?BC z15MA&BPJdBKA#P|g%dQH@$b=fhPCp+O(LyZphJ7@vw9|e^991LghNzAmYHolrqU~}0rta;aHNGfL^6)T$_q;UM?mVR*`yoP zAL!EcsAVWa_a*a+G%8^6!CBQ8<2Po5l(W~MuQuaBNi z!5z+<~e)QaJwC4b8OpO zAqxyJ{LoEOHwr;a%6DqYT9dV==h6feydmu;Yv9_u+sk0%BI%33WRfm0r(V5VC*SKw zCcZbQ%*tcopEqVqBZ=LP(~O;`r`eyq?NDsmdo(3{(eLsCpU$4zN{t0^f=o~m2rX+p z582BLo-+0X>62%sJT&c6JmpA^?nHlYu7~2Lj`ZWzuYPoM+lLt|j>A;9;~-fXBG0U) z&}C2I2t6F-xjvi4(0Pv6bGOU~mCrd%ztD4h#LWp@=3ar`!>=A=+waS3x2JK5l?*?S zN;<~lDLQ5*l*SWJOc`PLa7dAOBO7)fstPUz94C1nl5@I}F1jXx@_%%lQ9psQE{;Z( zyG!*`g+$ZF4a8Xl9)%n?Kuj;!qw9Yx<_3&BeGWitx2xtCM|-N+l|(0gWM+f(S5Qe; zM??IFL!?1k_&x|;`MDQej{vT&UlBOtt$BQ@dD4#GMf|P{nh&Ecf@cgoS7Lz$(?rs5 zzOG$uC%kretwt=ZfJ4FfY0FviP2mxHyZZkRQU)Xe3MtVObO&TCOS$Xn&U0-|m znH#`SexRmTG_V1ATuH4r3*R4Dp01Zs=fmG+LizY|&s%&+-N9L-wtteed20&(mDTom zul1TNeM84gkPR5gkzug^+~|AiP#`=$_?qsgBWG>@)#MJN1|2ORN5%G*xLGEH(fZMh1g2MCqjKY~!p_ zo)_l^yx20=3-Rd<%CnBIFT9925A&TcieLKB{Oci?8WT-V>eY^D)`+c0fhg+!<2u*5 zVO6ckOERYtkr$=l{VHMR0&~!ms}Sze*(Q?Bdh1((JMEAB2{1rtMOmXL&sl>e23FDe*T=4rcDW^(s^WmSa zvZ-`_lww&_?CC|$-yD}ugFyRra-gM~{xMGrE~LJ3YoZ)g+%tK$U#c9t_L>5H6=>}O z4>N!@OBukX0D{I(8Inj=)dh+dL85t%YqI>_r=`ut;Bcj*CJ7`eh11|yThy20hnP&2 zpu6APO$b6kZlSZ)QP?P@Vp)j}E(rT=75E}i>#%NxVlHx>JuQan}sC8D& z2F%R!!_MUG%XuPRm$L|?g^?ZoVO)mOw8rTn)OAlWykrsoHZ0)#$^*88O41<;+VplN` z;c1}kge+=?faktFktVYwA*(|sxsqm~l$sR?2>A!uR93}s7c{O8g^UrDQV&z_WAZ@eCs$-*`I zz7%&tj95B-B6sQHYH`K!MwjE{Sl52W(-)#|DS&+{Hwo9yGZLRhS;L<_xM3{OiA$6Z zt9F2HSgx6j04#Zd=R4T|&+bOW9*(`?sJ}_VsSYLkf4XwVX=KbQ4&!TJ5PB~>y2i7bri*)|m-LZ4HG?9=&XeN2Cd(*4uaDxqUfFA=T3c8a)1_06!%UZKgh0m^HjY=wBj*tF z-IC7^Nze(@3REcZ{n)S^K zo1%V;Nc0|tA2TTvFQ21rxs}$^!G)d4Y|o2rc#Nzfam!Zbc18kuLQ35Hdg0?~|Ig7- zPWfXaRIhw(MEkfo!RKYHSHe*(-3dg)qP;o4%+eJsRDuLjw#1u5(Poy@mu{p zv5OYg(o?#e38954!F5{-x_;wA-y5K2MUD}s@dA4-S#{tp`LFmJhqghIZ| z2RMzM5VCx#-_x+Y@G=-5{a;_^a*p)_+nfo`b6hSSgSs!c+2_i{v~kz&Tq~7Q3in@r zTz|ULAbhSWLC(kVZYYcICs0W%JDD=XkE^hZ^3tfi7T4&sP@?LPK2~`FRTBXS&@4n* zFu~jP7Xq*|6{Hi>#RXM!19{D}7CGNCQhgRB%9wg#MZ!hKI6BYiHFF0yUGC>}?mZ9U z)NO02BUSd%s{~*adS<4kl{=IUCJiH9q?9YHAxL3pxeI#|OEJ zEtykPPvVB&?;pf=PetSfsmh<*VIe!)>Kn>`6dQQHO`epuKrGfZ=c?qJ$mx`+&s#qn zIgy01K6GDz-Wz}4)ajc@U@SOdnWjA!JIqM4?>9_1_!U387wJ%4VT4?&Lx6@371PH( z0pp$jq8<5r!bLHUBRZc}L%XN|qrNdDG&!`ePic>D^<>%Z;beRYnK1VV?vY4I8uP`3l6!@be6c)dl=Ft8ydy~Z8WKI8LzI>eh{h1 zt~79?eTHCDnA*THO57*ry9j|N@|?Xl(p+mB>Kb?b7YrrAG(*`tr^D@!-G(0TI4gsN z8yz;{^*rq*&+<9|ZA^^TDXO7?4(d>FGg^q&j=L?ScLAF=moBSqk7!jb;0{T_Ub5GHJSjpsqN2%hF}cy z0O9s%XuUA-;n=4gse4E8K6Ip*{x6vFr|+WSe7t}I>pMS6RBkaCY*>!N%K<(!>lDbV zu}6=?aUwHQ{^c%ftFa}f^I?9T?HwJ4M(boOA24Oss)GiC&GHpjV_^sV6nv9{!*(DC zEeer*SrRPsT;s(f}b-{cA*{R;C-j4MADVV zn6!DgK!*YKk)%5qU{(v7oKjr)T3lhio{x*;P)c8<4ap+e@&PR(VszW|=2|mINZeHc zXU-lM!6LwVBjVhWrR0UFUy@lztw$%eBDKF6Sejuk>;+@3;*G0EviTtgU%w0JwrThp zmHNYEuPm^qz6kONN=YxOuySnPibQPgnnWPqcu`vkn4CsL=GaiPlruvs~mYF*VADC&UM-QnUN~WS$iyxtiLMj zIH*|&HfE4S74RqKEME_+)TO8pZP(IZ8mC>=(;yMwAVFnJRLbM4?Nez#h8JP99MyY? zVLQ}3yWX}j6Gn#troYx!plzHvr(?KO=pIX#m5@>hM{kbpq}y9i~yk# z0AyU9KNl8gs>XUzyUIaY5&gMZzIkVF%V`T3+ST?-E^`^$U+*lmF5s@OIegH~5S!8i z#5ZBCxnT8Dhkj#@%tBP^OsPJdfIq*{kCDAto``7TR}razlV>goMrIiIe;h@-ia+as zIl~aB_Ie3VF&#R(dvy}%S^iVMqEkhniTqWdr_-knvhQ|qm7SI`ZI}}~GI~StVb*Rh z9OT2H5nN)RSO_S3XdT#o8FB>?Kp|1!${2VYvptfqVWLdqgrjlATRR%Cf4ONakU0zj z@UTtFAUexhNHytd7xu1^PMbEbSS^QI55)&I1g;o?on1Bn%C@^9X%7DCWR{N0vMbH} zXZHbaiOXDmxG7Y(+q?9^{tBlhtrfBlZeCa&>E4AICy@k;b;AgB_ zAUMrP!TyMW+dvFn@E2E(UVK~b@#<8PUc*_wm>=a!DNT+cC|6-TU$3!Ut$u6-XzPmK zW^MDnQg{Dz<;Ja3rD`8-T^$^Kx=1K4)wg~*atZDqw+P|v^A?UedD~1s z;^6`?Y$4XtnDT2PFdiWg(aP^FV!z$&Z9>CeoarPQ8!k|<0SiuWvV9B*TApCW;?I=Gm?@;*k3Ng)Z zV_}IM_b}e?{H^@Yr$IZmsvAo38!~zK!VIXB%Ezu6L>TSIBRCr_H>glW`)~hGFodf4rJt@3WEz zL5qjry#w|Nu2Q2+ID}1qFSqkXfUP-2u?R!xFE*MC$M*_^?1tiZ?MF*D?zm4;E8q^v ziG#|cyABNW4&y>ebuvJd&|9|9`dbAx%5&(4?hXH}3k7V*$NoY>5*M9sKgIJIbHSy* z95sSq91XhrRYB{4Q4Ubh=fWQ8d>pwyPV;h_CX^=qZp5o_Rv86r`xYqx zcI`I~QtMX4^K{IV%0ziMy9S#bM&!u=#Ll^;%SE-0I?erU_u1XTlch)I+Pavw8v|`# zPstwgab-uT$I9(bQ?d55nXNE0@rB$fIlHe-_w;cAl?gklGKr{ii<)8`%1@_iiA%6 zIc(JNb#toa&;7*}Xk)D3IfLu9ge7x{Bg$biJRSYYvT}6M(W$>=1q$p{_38%WsPwz_ z&;9CbZVIq4*1x*e(k#PK@)zQjNPrZw9DN1t0AE|B^z+I3qb{y`LudpeIv(lt;_X49VizGV+oYd@f|tQbFy zLJcYc-MmXzxTem5udF+5Jv-)unTwsjSdI;^4}bDBG>ZbgUf*0)BNPX>(ocvir|+Ec zJ-+B3PlI?DUSM_tnc9Bf>xg$sAFT>mZ;-DFEFaMUd!qG-&R3tyVtp1vMJBqn2~1lU4g1 z5wCzI29wWj@7LcXN;3K^UY1dbEblM6{&Y3@Ux?c22ZzcR`&?CgO(TXr3ZbsdG&tEX zc?0RUpV@nJ-znNaY9E?^(HNgsP=oPY?^z!;2-i`@{uo1MO`XJLk^FnJFEQNk_5rAY zutMqjop$S%8Uj@;YM0iROt1DO^h|!W`IaYgyTvLf&cHTk&X%85J9><;7&Q6mtFBot z@GNLF!_iz(?&0qwR>XN6oRFr&sBPbgc~X8OnIR8JWqB1T5f@;}d~7loPQDNl*4S!s z%}dy5AJFt-6#|;(Qf~(MM>dGq*^C{2 zR{?|gd5@SW6WaFo=nBz7TXUAV@k-|q#FU)Q%aQN_HXcU?vTT3O8U@ekdTsb0tSkue zKG3gCn-q34%d;x_KOtk^0&ZSctXn~3oRym!{J$)3n8A8H&I?=O~o+>Ty-i;9LsJyDHLB zLcetpZb46`x$31gSEf?vBcLw?FHifv2skJYIx3LMCz~Oh#Es_R@mgqK;@x}My?kf8 zO|~4z>uKh@-k^E{%us;rzZ_z#oa0|?6vOlC?;C8HGdfd(z;_!XD`EXkTe5q5aNAQt zELAG|AviKTpX}yF+rJ-%!a44mj~YHAzAqBY;EX^QpzBTTk%T73p1@K?gKg#gh)sde zOR7SHt45;;Q;#H}ZV@dq@{*1i_3ug-)q}xw`dbwY5a^Reg1JI@y^hCu#Ndaa=#fB8 z+M2I@?CC1)luv>$zUtS)E2PZw)3ID&d@V*?t-B-cE`t-rAxI^y2}gL9x`bg&o3(8I z!4hx>d5=_6AT>^5tXHO6WX9qtl}gE6<+ zMt5}`3t33HKY|>;8M0jZ6E;-5c$fmc2w$G6Y6HMTR3{s2h4{_~r)5tWM!F9qb3X^j zCod$4ykhBsSSD7KVy!!i#OmC$I?Nhq>hY~i_gZ;qpCiVa&iri`%|~sn4^zDKg_hpv*R=c%G+;0~FtWHF z?sdp}`ibWS(~VeQqC|Y$)~ySCl;v2W4n-ySeNsY~Y?u|=$04So9sD;R{5%5Nn7;AF zRY-Eyo}T9=BNLWBrNag$Zo8^PA6W@)t5g06 zp1j0_5=e|hyWkO~zu8JV8cXQvS4Sm%pxIm!K{HL?Bu9I{{Bj!3J*O+ywn)qeLJLGh!9@l0hx=}0dtLF5>)Q1LD%wWn+-;&P^0yz_j-Ik5SiI%uB0D=9U8&L5rS0$W5vh;dZ`%Z}&dp@Q8cU$Pb+CQP9v$RdPG-Nav!;~`eAkY+tsxW87oA|U+G z6S9S}d8_8N9?|1`3=gD&MhJgcYV%B}QZU>&?5$P1?$iO}n>HT>s#7t< zSFL=G1({uMW%Ug0QlHC5xzxCRcnjYdxKuMGlIUuFaXN7$oMR-^UE*W_6-S~jln{b} z1;^MVUWSuMfN&25;3gFGUue*Y@k-HzHo?`Q8}-Mhjc$!IZUVEV1jvOhnL>8Not;}D zeC0SI`l)(-l}@s6OFA?^Jy84;>XZ>gqFsCvdc5mVR8REQtr52bYIt|J7!pujuC`fj zA$Gz|m^u4Ye26abiiXwZDa1<_>+hJYpi9UJOo)}aT`zITHV*q$UwBkB%QigDWC*xDTDLEUj6HyWej7N!4hcz! zpArVCb4ODSjqn{`V~yatrx0>slxgrxpEdXN;2mit`}fj>z_4=%f!|FPhR?F?$mSoq z#XRL7SMDwHNV3Seoa&_nIF9b3jz|z z=dHR-wN-}ANScbCaB+V=0e~GdHl93;(6}zopcQ9^AKc}zQ87rkK|f&z%78zIJr;D> z5fWxo8()V%h4kx@yM^wB-P@j3kOS1{w${vqTrvQGux3*|!6}j7l%6eWI*O<>_cu)f83`oBZv zi@FBmw~U~`q}QC@FQ*2%p)d{OPS)uK)#eD<$|WlhsVbFd?}xv(ss?0NC$K4(&{qv2 z8lyiMRe#U&hAD>kTXyc!9*RupO3BYUl@JV{!@D(?3KWX@WaX8xH2eBf#~(Mg#@T5dldvL^ zfLc$%hvkS?ms?E^b_*uI<|f58E<=lqv-2lW0u+nD-TM$wO@}!$ked$G7rgP-5m@aS zk#su{D6fH4`{LhKxFfBs2YpIp$n#bosKO{9g=T3?Dkzz!bEbDU!%V<^iEO7G>?Q+1 zn%w;(owgE+Dz?9q^Hzw${S@I#M)9<|X~Z%UiS2(_H|G@156_LcSQcL5Y;XJ+{ozhW zD)3xa#<^Np#8?+o66TwY#)PlTS@qmtMGvZT?S`_n&|B_AUgsgtitKwatkHL$bt4xL zNsw=ZIj+MVKW8v0?8@JhWws#G4j@MTkJo{Ssj2>9V)i3fQf(?*eo9mS#j~Fg`Qlau zEG(L<7WkJYzdK4ygvd`YpYNu`%DlpTJ`0`X+Xt^L+16mIK|mdC*d8X9!DX6vgN_a? zM(PYXG`{k^*?tkr)Z*ACdM{Za&ZK{`Q_BqL2rqXBOG!J10O3p~%*Q!F{yVQIp3tF~ z3)MCYy~48jlmxXZrRG`j(PvRYlAt37J3n@$<#&MZ>j`!SH)L~_Pw(a`gGlFEK%$je zp$PPYd`B6;#yz68<~@ftaH*}GF0KHs&bRqFxs#ay8qUsnQU^*b^nx1ke)>uQp8$gc z9NmSV3Glr*=be^Zf?b?sp+APFKqo9#T>Wj zFhr!I@ZUo_rFaCI+;4Pmqp8c;{JV=`Xeao@Lg2p(Z@!k;`EC+>(pF6EKC`Yqn?NeQ zUqT`cG^GzZ=A#G@9K-Xu098Waxf9+LGa9hDCwZ;c7RBWY8z@3*Vw{XCK_)3wN@Wqus?soV9zv-Ch9pGuEYK|3|q?|NNP z9;d{1K`%CY5hD1}ectXV({_E)Hh%0wwOW>|2EGkUp{!d@s+J$;njJp31{a?MaMC+k zq%3v(avsK{d4`9LR|IwB7zKQ;re>0DPjUK)7E_Z-ojG=sz*V{?fegJU6~-wipv292 zF1MD~t_16J*jf1F?!J?mpZc2`oJwN@)N$E~AM?WNk9Y4v-pNXcYP>59=4?b06$a0) z`G!t2vgjCjuK98KfVi%_?UeKduEQx(;e&2paqXb*$A78=ANT(h;Z^!KFK;3dToqrJ zADLiu7{+(q(2X|q2OeFMJ=p=~H}LwWF9W2KjgpsOO_i+3eOQyYXg4D8TTp`%$Z(kn z;Q8YPmB@m)p;UjGXLTE6$dZ{pUw)>Brgw`LLB!lIUfPxoBK~s~O_yaijQ{E3u0x^# zO=j8udp5cZJgm&*pBg=jO@VQS;jmOfUk6op`bmX3bgI03lYS!9X^RDYt0`%J6uPe0 z5wC^2=gm(n9VHZhdQa*dPe}ASuLTKGuGpA@oG?3YKu*W2Zjl%=GQr+pqqeGHEbLVO zz3Vdu2k)}1vgrv!@KKJpSJjIK{Mb7Hhx7c01RV%Z0}{HX)BTdSH^ZUyIOxBpJ^7#H?o+wHeDfne(S9G^`raI zjT=QhU1az0whl&Z!c71(Mg7Cly}i-o8GF@fJFRwGzDp0DxGMFlb^FyEB{reK_Vq8D zpVm>^m}91#$@(%R_GO~do8#@v$yF*Apd*jUd+MN%Ma^%fkchf z{4s4!>5~0V9dcF1>ypAbU|q%ac&j&&HK&ZT5!#Ol^|OT25x=_K6>QQ<7K)$fgOuq( za-w+T-@Q99M}>V!Gr~hcbA)VgdX%4$O)U@^Pqk-8VZ;&e&|VyvnRXWx#X>Tg{){>* zWRg$!FG)kLlmHpYqrOMq`LHuYq>N{bXT8dm`5$7>M6n5s_rCA5thd5L@(T$%Ji1UK z2f4}^n?kK*%69;5Yv*qVX0ys-i;q`zlag!^huavxsj`!eTvEV4B2d|tfA;#e|tVO(CgL~h}8 zkUD#`<}IuRz};LsvRiUq>5^v3S$UcuvGeYi81Zw*?R=Sc@^c#WBX}K%P3`fEqY-XY ziz#5r5>_McG1h6wXtFpfOza)W!RqauCKd9)*@+G(0uY^4XPFDK3FPFTrK#*7%uA(~$ zh47R~OqWhv`e)ceh1J9bnhZP54>dESLb(*nrG72{SzzQ-wwn)szx4;fR5uny1xICM z^Og-6JQ7!|3dL6>s(M8^A3Tsw(*X+;M8K4iL2*o6i2sGBjRQpQ$9=|>a-2RDr1ykKpwf^tszvuv@+;w2Qg;E< z0Ml&O6`ODWrb=NjKgg}}2=GQW_g)%oTH}~EY&(!VsJom+m$KTWda|iZ+M7Gd>BHJJ&DuF8^ z^ay$DJsn!3&S#oO=7dPyG9~sAmlc1BpX{AnnyL&SG0(X6;i(RC z3E#S?LSPwH)(c%EVm^TMd+jX|Nl)dsy$I482ADXlhD>URc$Q-2CK^=eXPfYwF^hyTds+ z!GpU5cS(@oF2P-cySux+&6SzC_nUb?;PlyDUDaK^YSn6479AEFX*mkOKsdFL?6(}8 zM8Hcri6_A%+vp#BcBf9rhUtG=|9I~(u5Ap4r&wOX=Z^IA?eJ)vA3DPmqDc~Pa7%4U ziY7GM#eanoS@WTpcNIQ&h3&ZA|9+`C18=2TL_r?Z*5m)OPRhR}y}smQ*$PqjYi->u z1FhiC-#b`2f=|zA^jE36VY}hGL%Fr0kq7$m zlCY!+Ao7D=Z|+VN?zOC4OmoTT zhBGBiw9-$GX`rR&p_h76;dkn9-*w*knMDjLTmZUzpvEF@i(?XE{2CWVtP&34HXn zA0_F&TZj=06I1#m@sEIZ>L5RnAB(8UQU3U7A`PmR_)_p{pvXv0(EwwF7#PwwlsxPk zVcw@vzu%nwQjz3;rd;r6SafWl=rC!PnR-bu{9?MEdmJ>(+dn@t!1q!yJ#)~&dPjcu z+3|oDq9P2zU8bCrSYhDI0g_?Rdkwr^zkX{-aANF?%MAMih*&@S&hws_KkW>NVy_|p zHBvyhB2ivJXl?F@)blUOm=lidc+y8`ksiANIXs}DZ6v4f+z${b`^N_vfHEuJ=Ul!IN=T;$cit}NUn z6%Yfm0eOKUKEz{!g1j<${j_BodtOGVGRe^K{qZjscWk<9X2IJ5+kx9b+rir*+h4Z_07eon&WxkK zeGG9rxy(P{K|uDUqeJ3=QgG$9NUiYBmH>vazJUT`byYW1_7o|Ju+A~pU(_f-*bvoq zh1oVso--LAO{!YQppU#n?EX!}sQ`|M%Z5=Io|6J6;?+)XFitVvh zzj_OF>w(wm*KXIi*8gyc^LNnzr{{(0_4j=A_4;$U>}f_mJ_QGx9xA#kW@NiglpE9* zu{xL(aAeo-a@2i!1((*TE~J%75-2nPVvxrG=5!%)evpPxw2)mo|2*GmFPEYg8^6gDEPi`_Q1>B4Nf{BcJ)Q zcq*iOar{fdf>O|Lr!tA-i~1NBp3h%g_;j=$JC`MToM+mJZlf|1lQaJJ@7JKYVC9Ea zyo`Heq4K1UKc0)!Jel|U(5(sAlm9OAV&ACbsmM2EzufO{jq`{HlD|R?`b!;@Hy9C0 ziE1cB82no(>xH_7AMX)%_hCnXzCk66Iq)gmD}4i7XchG~ig+`VCvITB-}0}>7a$4d z211>M#dtiGGtQI|^DbExvM8l%zU)Yp)y7u({x#J^S4gX4NcsZm%TGhk6i~{z%l`M( zt(M<0)q$g6@ZHzC<#WrkbiQ+$^sX0)*s@iM+3BfxmefUV)(S~)hEkl8dkA;Z+6J>J zF!diBO~vX;9o_tK)BumDbQ0bSXyPWlH@) zN>RacCggj86>0OuxWI+UK%x?F>dPYc+Pjd}=!h3HF+=$WYZy-X-JJ?0UVSSdJux*tL*x9-zBR$I@ zi0ctW2gZp0S|;@uhy!SN3PK9=L54tqe?$5bCy?|5@3)#SFe#2!<)$Rat6QIPDAlPw z_~%n!=F&>4p78j@KZ&O##YxA;lvY_OndyvY)P=*x1_$-Ebx?@u|9W(GosI0ozo)mEYFBrmKJfZPJg5 zI(`+*CZA3>t=ghayhr@y>V)UZ3CXe4i%z>HfxxC5P%I!XSv4V{JYhqw82`@yqK9&_c{!@MxAy_bkmOmXt< z2l-Mu;!Do+RQbb-xvq0KA>pML_1>tqs7Qe|f%IyD74b=!@yXm01}0;&%~VRo^s6~n zqda~q?N+lHFLSi?{Jw;hS-r<6a{7I&?A+y3hga3a@PG!jX?h-Dr%yJ_a7h1Q!*{3> zKNyY-AdMrt*qJn?cGPz732T&M?$kO8%_2;TA}B%Wj#?QB7Z|0dKiTBvWIatD&E)89 z=>M0Y#xNx;lIN>(TM}@&`k?#KN1DYeW1prQt}6Afe^5p}t(7OoD2L2OQKlBBuv1Oy zP)u%rf6leQ(OjbbUq(~Fk^p{f0iSZZ@#fI8{nOjMYFN1F-Ci6KLC4|&6aDcFMtjG0 zQcym{)QStf1q$Y#aPt#SYmtlk;ri8=m8k2N7YHa=Hprtmqf8l5Z_reH*~p7>DMhe9 zb`DPFmNED`^4G#lzW=D($xU299q%|REm>R!9idC$Db5=E6gi(P;90CwP^b}nWv?k{ z*L(jWs*jF)h9*JKTZs+#5L_(K;ZSETNl(yWq%m$o-~6E#2|6Y10#>S53z0dRGHFiT z`1^|GBQpFykA!8VR`SJ^p>{`=%H+Z{ey)c8L>M z+`9T}yVv+~QZwL9DP?2;(HgtVmQ*(xx!)iE@1f#y8xmM%d;R+~KhK3Pu%qrI=dvX% zGe_l9%l!0`TLp89%M}!|lV$bCxwN2T0Bqn0N zs)3PXj(I3d?E=ju3;JBs$BDsw7=>~?5@WvqbbG;UpMDDG8WHK5pz@H{l?p96EoKLT z{nB@~^vh|V(@TGk_O&%5OJ;LV6fS>il)kp%AROq6^Jk$^`Det z@YRjma*Pt{x62JH|GU(8GDH`O4E+1EI+C)w=Z=Gy z3<=Gf;Aot_OcFEL@xT(HIdN;5-4fCbL2NxWzwM4Fh!^1ZbbBCVL z&ehBz_5I=})BUbwq~@;Xo2wOeU~7ZMka%8W$1fD0+Wt;FaCVpNxuAneu-fv6EI(=x z5Z)eb=pWK<9jlU%%3^BZFTYpA_8YVM+?l=g&150%*P)O*jt-<0(@@uoGqwRC2B>YcQERRLBlmcLlx9}xhz2DmKEgM3Ffy6^*+ zMF%-_quz)HV-ccOx1^F8Jahnz!W9|VEs~9a)FHkrPdYP|T=$}$KFJy*^tt9RpVHIt zu}PRYAO|ez{qw0Mzys}2n)JgYgE-V?iJN>z<h|LMY6Dkt^vCBoZ~xwGZy*vnPEGM% z%em#w##NBe90bSU&=y`x{6eQhVla7^<*Gr0% zYsth5srnjjGl$5Os454d7RMj)G#uC-wH^v&*s9+FYb_?vUl`|oGU z^(|*Z9);e)szidIDBGOB_9xVg6Sq=*rG!cNwKs`7q6h=-x%wf=DG8kFGQ&~JE7WYf zMFsW5k}w8sU~x4B4o35Arud6KkIoD z3c;N}X}9`0n0FoaHMpd1Cacv#x~Z{5%U|2TlC%P^G$=`3+&DD(6?>Hs@??;B^!_Ug+^@>P1R$KHT8Df`dl8!zdHvsp4}p-PabDVe)4TFaD780}^%GK%hfIiBv2%$WBLP&T z2cN*T5n%zlCNO)M5Vc#tBQ_E9h*Q1&dBtbE*%){A zg^U{eBxQbNaBMwTeT)4gue-+gUDn(kDY^@@Tl=yg+!Fp@N3 zV9OyRm1Z8N1V>8C$9z>*{fesGPVEL6Z~-V4m^RYkY*K@n$1paK|M8P-Qhyv;x+QXC zXR-0HT$6;%WRp`vsRgYQRNmE-Fa41Y^69D0m>B=PT7WG=0#S8x3&D|`4haibln0C{ zDQxX)RQuOCzeh57{iFIa91qxwJbEJ?j3l)ONtVU_N|9cCmJAXUZLr3>*2_h5g&?&v zSqb7NrQrO+AT8xKg)U$T4}s^wuRA0OTsfwcZXrdQFho%P@wsGVJ~*@{OF07a2Jk@x zYbVpRlGEyBg(k8)whv9RdFu_q**pRN72Obk8hn(%G}YrQI;}Bdg#&rKvciT#D0Lro#0iGC<2N(M;0BxpjH4mfNRDFn7WSWhhAw(2})r<(i6j@aI$*Irp2k_(7O@Yh?7J++g(>q}#>JBTH6 zAb$9>KP_(`RNMz834k;KFyCGfl>fet@(|KKsy3)yx!MRulXN!cpp4?|U|b;G1z&3l z{*6uibzuq+$|_$ecXN2Xm_8TUjnkT3lfWPaAW>q^SEz47K3%}vL3{e~3F&5yfcUX7 z|9M>k&?^MQ*ZX-qf+*OB5&)Va)HCp)?yrEFZ96KyLw|vH7jbPW_^%rp@P{nVvoxCu z{S3bYUE)3!oEtYKjtgR@0zm0q)dg0+-x+}5o2$FYXvFCxV&_g5+y1K=;n( zwRETu(Tk}FMM~x6EEI6-7RR6H+}~HG7kk_eMtawPEs2*l)9d$KSi}A$WL$hW6_-&Uc z`W>ccDBsrY*?(e39Zi(ToLzW)a7xy)2NgzdbkL+95WigKWMX*ww+LmNZo2GfUf6pP zQw{tB69HyVGpOkzxt}kj_U%66g!^hrZ#M}P(LsHO;2GGm{ush1rhCo<{;L}C7bOh9 ze1Hj804NIE4-m#jg{}7mJvkQ{Dkl)Lj+k6yraRmhS+fN@h8G|1Qn&m52KfHE`vQJz z;bMEvFoahd;$rof8u7TFOXj8f(Ug91)+}XUX@ha9dk!r3e1l<5u;3o{x#c8_?%Ve1 z+UOGV{K2$w#r{WA8u#-CoUzhCRb51Bc zk2VM5>Np8*5hhOArpSsMo8ED>$x!_#{sEYvbAzyh3YTx;s-B)0&K?2+3t2u08$qXO z09~J;-CrV~l83Wy1|DZb^SW(d+CO;B2X4cqeeQL%|3y}pMhTRhj2!G!Hy;1bW14Fb zATFBkusw$l&%gfLX@x6IDyVlO++quLr$yQJcP}s29uBLVC%o=J(>P8yqxK&?PH+zw zZ(*#}pWzu(E4otNwB}OXJ4=}~^wXL7o5H1M%L9yQRPNP{4-opNYNoXXup%E}J8^0! zc&e^(Ib6XFWDw8gPRluN<&`jHCiPhoPXcQqX!L_Ba?Tl+n0&pZ zm}0#pqYg(*zhnRgJu3=_l9 zIA9W8qTolxEoUaDpGk#l*Qhkachz!ZjpnvR$~_y86XU9*KG}y_w}ygnX`i}YPkb;A z8dCwNmgvMNW6SfyS*_LHflt3z@hZaN5 zt)uPl_Q*(DlvsGCUbbfFaR3_~8yokwmtI2q+5i+kOCQE4{1v*;h2vBUcaSi4%Yf#? z0XK$h{tFFhZx9PKP{npllM~gDE*Mwop^2Qh>_RA&7t+m^8{*?LxV$a*m<#Is=dPwt zR;kfXvgbGg>1O#z?X)$>HP>?c>hiEIYELaz(&jDGs{PuU#QC(YcQw^8v&Ln^`R0du zSgKKx<xN(QV7FN|OPwkQds5 z{EQ6q5`c_%lbTu;*4!+j=jP-2HNK~Q4DL@P7A)eB`7A^Yn9%3h`5E#~bDm52XSZ5I z=_G2kbmVm6vdABE5X;CpuD90t7t-4yVmweRH?h!XJDxmYx*PgySq)<@u~0BspQ%w| z<|&Z&Vt~1|!9RMdD->tq^3@WBn3PqVW(Btres(% zhH1Cuz&mMuq`fw_DGh?BXgQ{}3}43R7R@~(XF|Pgp&XSW8IrXX!3leXwDR*J!*v-Z7804A9ABuueb3< zq~ILRMJ*=C;X~EQsuUEdY#r{qu5@@%Vid8z-l`BR%e7vz&>*I&M{=5KF7Fam95=_~ z>${<(IzOPAp%{+qe_a~)L=j*5E`iBi&sSCEF@p{;fP(I(ql ztmbOVs&N7zAJ^3_>^Ad4e@bP+A34K|9(gvzZGv@n8+duX5cr4ePK^!h)|t5talI}VZ&TV0-m}baVwsQ7KR;aDMTBtIwS8he7xjw=c4Sf8R1xo;`d&&aPUcFhrx{Pu z$5Y>civohR;{gT;C-pMaTX)9%=jl@}I@d#*;uu9c5%jybYu3B;`AwLAC2C==MErMt z=#*3yxuuIpv4k#_=}Rj=xxJ5g!ik&S8)XL0?F#SAuNP=#OPuH3&c`nvI#bOVU)P(q zl%zIMTtlA1d$F9EIr?6$g2pga^I2FEmy(z8l{imHP&BGenuYSk>9tPaJUsA7aR#(@ zlC$5uQ6&*|U-R-DYgcYsx>;H41zr^r@jm((`821Gj8zZD$Fk&%9=D7vaH3~U7Fvoz$i!sHqLyksRS&Y(F1lz+Ph@JQyUiK6I7R0=PWxyFf?jKLgR;Iiq!ZDI z$#Y@_vLjThH|gF}detcZeA5a)zZRBFp9#$B%Tp&8TZiLCg<)Gz&n6ekjI}}bjvr_% z;M^=F67)u>_X?YvVG}W_=r?NSP zThBk-jkzSVikCUY$0u&Md#wz?i*NXxu-msa{yGE^d11#~y*fRsQ(IpmSh+P#z4wxi zOrkB92Emx0km2yJc3gC9Rs+pwwgd-v(~VzXjc$4lD|h!w0!6DRj_%g{rjjL3I8V>m zo+mv?^Vrh%`o9r}8S{&O`iqnTHAyqhpH=`59rEVs3>#rRZA5xz2c3uH3c}g^-9(MB zaw9W}_xevL)z+p7mC~)B+chuI4)i&=_`f-x^a#}6x&g>&{XhkX((1R30SXq&ud^ZOVxoTq179JSQ&YyL9&{fV}L}};2%1q6G~fs zx}lY!pWCD~9g*F-{BA(o1(|ujUM;P<^L*=r;p|BCU)&RfcXautIyOjy2dNM#+NWoH ziH>gtj}%VN1_#QR$6Foa$?%d@VgcAhje<389u9#DDF4uesk+#(`=zK5$UwO>IKvYS z2{tFpUd@PC8P1ymp4GOLQ+n1OA(KB**4hB>G_=)@-_-H73_$g0+K-3c zwI8>KYJDfXyGcUl_BHERQ0gknB1XP+qcOp_Mo^8+eQt4Wk*YGow&tXrUX#EeD-x<- zy+}lM)Y`Pv88Zo_*VR#iRo8bZ&G^>pnK~5AfN|`Yd}oj;n~Lp(kH#6*n{K=iV-9W+?joe3Edk z9?!_FhVvk^XY}BE`tw-JIY&wKxu*$OJdg&@byqnT~amb z*eBwwHw~+ek3|$%WM_)P+zJcn>m(#?4qaqnlFFFYbCQCaQ8oqe0u@Sl=b@Jtj5tdfOPh7@6%}IA`6> zu-3v6JLUHwy37)V28*FKC71V17q$#AfQ264D$5M_UfIjrdTFEL@jPiG1lWr*m}@@v z%Tfw;BYSAWM>8XPAENWF>`U?6ZKQFTG!KYXs)XAk&jUUE68z5xgum|-b-l7`kWv-S zh^#mgWz#MW?dMvzgG&}~CE*B}-f%*OgxZ~1WWFIng?Qrx`YuWMT`=fs3pn`@-(vV4 z3C6;juK1EP^6}p2jTqy1bN1i@s=FrxL)P*nW zu-PZ|Rp2WlK&pOKAkg1?C6fZQ52n38$>mZj&NF(mdb^G$O`=du2E}dvHoRCiQrZ_= z!iD=>0(1u*Qzje6`ZCwSceKEgvoifHn4 zXL1CtZ2Ik%xk&lU{LjObVQkA9+bHOn_4b=Kjov^hNTfd*QnxU9r$eudME9!Bw)LW zd9Fo_&Z&OJ&qKD^6oQd%0lSF+oGato67kXJeYR;8;+yHlE%_;rH@A$Cv^79yDTK5y zwEjv%I!}2dmtLJ(TRJufwwThC;TnvvlGmGLbY$JW?ADhOJr&sUnbBB2A4tyJ8Po?( zKS}>AJ%m(Xw#D#q5gfgp%d@J~!x>J0%M`_seldrrGG)DuDj}vhM%~gP`H{EWpFW+YO+2@@-Dj6#xbF*=gj(VQtV6$&u8tRR6ByR9S=0(r2V60uZ;#a_$We zpzEUOjGr#CB#WUlJ-C?(x3)^`>UA794eI1vxzYLxc(_i=xUUIo!9-Y( z04{>#wLNk)Xg`gvG+plYnL*5H_jfb!;)TbK504u+qFxw=ZZr97L#>ZzZ{?jGU!xhsS^5z zCE%+cD!xh#tRQq<>E`H^E@}ENCOBkAE@Ec6#9#B~9sBs2$O!G(UeilOuSPmcrx)a~ ziy2tMD>cwEqDCxFT;KvuJKy1z%?fpDq2tiR5P~K?(;lN$FeB#LJVVYvrtt;7n77u9%9Q?S;P?jRF7{vCx8{c48^6xZ7wFoiF)Bc>|hZ zw1y5L4Z&@N*r_I}k9In}X@7J{2eL0U?mpqkSo*Abu|@@QAeG{mY;B3d8Oem-ni&)< zhQyWUHw>%&;}Dky`_{XLuiXWE*I+`-P);5?>S{&|iI#i%_jW`$On-0@(|V)?pc_8R zfJ4I`#kme4FVDw3Eo!G|pmtqm#g?Jnk&C}$DjD4**ro`Qg1BWs+Uxh5lb!;-8)5Us z`Vl?y#$260rgXw!l% zBGidaG{X9pHR@&f<%fU#tPKdGX$}!2lRM-!I-LedOFloioz&}o z9lcLnG5ujVhOLnxQNXG#0oB5{=NPedelzzY`GcT;$|F!&j#1_I({}udZ_1y%9_o$hjadH_?3 z+z@5JYVfb4i={xhx2%*e8Xl6G`MoltTyh-l* zoYKDj%R`ib{oDrEqJd?e-<$ET_y`Xe&kl|I-b3k{y<1f?NlLBgVDN+gmIO~x`NPZ< z+4G8PsWg?f7&4(9P0F`3gLv6cW$N+3vGle{zrEjpXoNrxuivNkyEoJXJF|WbZCPD` z;$l>)c4;{MvYph49XGQOrXYz7!@SO;NBM>)-4Fxf+oFnFg6*HsWWxsU&R2LaJrhE4 z?87rQ4Rp4@^_|v&7kQN5a~%HCPgw{|w5=&~-#67}*V(v+A?sJ8SsNrELdU!Q;B`W$ zV#4`$i8;VhcQMbuSC0Qt#FLxJPRr6E+!RTIM=RBqI^jHFD(!=b3cDC*gT-n&dS zYVQZyjh6RWq>)*nS@;tvQRPdqg&w4FwI+o8bcJtL1g0U|t#s@3=FdZ)Kv zFj@E@!A*F5I&mBNlK-8goyQYGiVlJ-($Fm$BB0zO3ms!Y-vUCqfHNo_mexmrZjPpA zwFb>UEBnJz#bgA=n&cO@x^2oALNXf3OfJTWC=6?Y%BD1n3|bbiP}T~n3ZI;)tkv869Po%SBtVwtWDC$$4R6sOp+wY_wHfM3I|&GQILI@ z88hcbOx5S;wE4YAR|FT!F0(|2oeawi^rO7cZ%bsEGa8v9?0VqueqA3B-v2y!Gz7y} z%AI}H=uHK!Kzw91jqqDubdUl%$qy>N4_lh2fx8i?j!|)RCW#1{DC!8!5b)2nu$j6^ z{NIrR$`?qg>hAgk@&#ZMCM_M9WEV2yAj_ZnoEsQ^btj*%^+1-KW34(yAg^sLa<;G-7~frM|a{L|7%6 zEmplK+4&Z1_@2uSC(^6iKSDd-914UGK?b$`_Vy>s?Qrsi<*_(B)lXznJsG2^n7UM# zRqvi*1;q$Ot0=@a>?S0{yU^RmmLW5=ism@EpM; zV*{%?%9mu#$Lwo@0D=g{s`R)j)4cgS>_-~(%_Nq@T)_uusO#J$xB}1oOa!MBN?YRb zI)Sx;9f92BlaE%cz*4yA*Qd#fdkdJES76bnWE+_g*VbD2*&|2yG4tJP5K@&KmRFrM z*P?KpAs=04OJSOOT@RT{MGe&)Inp&Zb`eKG@VH#ST4+mkMvwLYzFo$cCi(0-@Fr0} zsPJ&$*rVH+I81xoeIoUYaCg&^yEAS?Wk9tZ( z_knGbvb*VwPdgH91+ANM*q?dw5%@wY$_fO7X_i^8t(Y;K>W*f-p>@6r^mB3dDWq$c zMiXTc+}DFH=tX>ljgmJv;LxU>WhMy)c)GaJwgDI7PV<^-?l`-8x7QgdMW#y z=I#qk6TMM3-@-q^ijheWWOvCc%;W|rN!^!9yDxk@=6i51x#LZTVt#AQ))OmdROv23 zG}BXZBo7HMe+lMsy-1s_$%KS|wBY4V%pBU){o@d$EK`euR%FrR!ac|#jcPL#U%3BT zhh(cua;pEHfV5*is0xH5Q6QUM(bX4n?46rG&9_@HPx$j6eq;UW==k(lO%KKmj2iC}vPdsQfh7FEp|yPl-@h z-_FEZYd6D4@?OZ`R-7S^Q1;S=oKpJIIpN0!kob(Hk~`$%L#3W#t@dwM#}OV0hZ3#inL zK0BrCql>RRH*RxbMSR;nH~10vW>2*NcBphTB>l(eJCju9Qu;*&h8y>LMch!YVa9*p znB2^`5dw2cMMTzhS5&ak-Ca>Q$;rY3JHc;>x6(j+;VzJxxx08shL;hEDh2-deCg@6Q@6cTuy6uY z>~`*L<%%4z^2UP&Ul($ZXU)-h*KG>J3Ilw(ucCjULj!PYm z???RFgHh#Uu3?yq{Ft~Sy!h!N0*^cII;-1Uu5K>^+i+^6{=e9=e-Nm*VSb@WBz6Fl z(bVajEFM`RQy9{iZ-KPgBrHsnU(>#R+EySg{AKfPjavSG@UBWN#MKu#apCTarV~py z9cSLMtvqcPdEq_#maU@dBO5Mjeyuf_t1gn3%5TBlgJB;u}nD;(Y3} zz)9*tl?w49nTi&OV9VkCT1|gd8iE?SE8Hom!{cHOjW8Ad?ZAJOKGSd}g}S9k(li_5 zWRVE*vAuVe7AYePNTUQ8>JeevhXoN_en*4F(9gu(kYjd55nflO12LqR(YW0RjSf0G z09QlX-W57K$;IwE`H740GCY2vmS;A--^d|avXIY}aqV=L^6d6{ zKe)`h+VD#=hSRtQ#8>uMX98!agk!f&=8`Kn%9#vix5Jv3_HI^-nM*TvJv92wH1df2 zZn0sZ;wd$n_3!v)iq7Fe`r{n+O>P*yZGyXrE#)1F5&u5;&7lO74CpnMBKmT z`GzWrtgEaiV(i*=2`^gU{Wacdxttd-Dk;qkA7w13^lwZ&ROBsZ!V5tRq24AN1SEif z4I=bC_+?IfFm#p0yX9O~J}<#)O=Ok>rFt^~c}dEnWwHpgz}ugdPeGsrOg-!tAYLqT z6zrU|uREQr=KxjXX*!f)hK})u0@#)#0N-BrJSTUy*a~%1W$YATt@T$M*lAG)YYeic zAV8A7DG9KDMRO+x-;>H`@!6h@_wvSJ&vVWdAzUbo|x{`3ALsYZg&{sa$oU%Q!61o~k7`5QnloGG95?B)!JwZUPZaFV z2O|B#mgwjt;}M8-Ru@_J-k$%3!Q{;Y4kX&G^U?V1nSy-q*bm@EiM+Mp#V|=)OWyOW zY_9#^zRE2;H?8AeNsxM`i-OXe?l7*IvcO7}lhrSJDcT89I-HM;-yVNByuMPiNSvRT ziBzsNq8ds&kP@%g*1Y)@9|<~8X|XKk28*q854!Z*Rc%q;3|(k z_kPRkZYg5Lg8XPgHT<%$%TB_jtg5%vMZyO4oZ}BbokHFsM^gD|FPaV-w3+S4b4~61 z=~(8xtc98i?NEdS%jUlXb%qheG)W+6q@ZJ1aNnxpN>=vRWRCDZYQR{nd?qE;<+En*ix>J z`78=-b?)Jvfl`+C7RvIogeJ$K>m-!d?JY+?{e{`KsM9L7?i_FpRn~j6v^-OwGRmWW z+nyx1pk!xvAm6Z7gLe^>z9e*{*-4O1p0FzQKB?PRiWY6g3lZf z3a04N3EhoEVaR^o<%t}}m&xA$bf3e=E`3-=Hhjr+si!>KydmtQG`C(_BOVGK8(IAe zqH=(+WHGvbEh@&|`uU~WQ9^~Xr_IO(1=|6%P%%72K=ISR<|KX%8~#}ak8?ycSJPOf z8IUbb7Z;v?&7Ju@DS$%Voi9V&u%t-y=={r@9yEW&k*WKaprZ zoCrG)g>I{sZfqg+Vw4I9oxBoBW1Voyijx<@`?&KZf-H!Qh&N(;;=m>ZR~L_3 zWd-^n;^ze)B}u9$_l#?&a3nbcmmH$lqSpa9CCX6;V=jX4m2e0nE3PofhH6xxof@}i z@L5V#=?7mx=CS>bD;=odVNNkzQT)(unWy~9=4!<&9X?zCDK(rftg4wBfU1=q$A!(e zCib-r3^jj4Sb(PN?(FXMxexnbJ-=+y@2l^9^uF6Q-30qyi_bTojw2h_u3j#dI_P?@ zLRl!8LV7;!+Fx?aImltOp6ERGGc_LI`;Rum4h@)FQ=Nnghvoi9XUHS| z)G-b>BbxaWA5`7kB`oueLAc}c(#H*529|@5E>VFkdW{eqAM}cGdL?Td} z`-Z0vHlp1s9oA>`tbB7}ld?Q)pSrp9o515-%ZqA?gx|JAfeL+0^zI;e9th-8*vvxq>|6n&mt3#sl`B6$6%!#J83eXp5 z6i)h%yo*>EG@3Ubk2#(17RAS?8`6hhPZ~{emPD!v6oxmri%bN*%0p`a(l?fq=RO|w6J>N%%IJBVcPGIhvVJcF`}}8y z@Zb92B2$=~SY$`Mis?j#Trg4P&i^#U7-}guV-4n@#wSo=8gz{)T%cbUM+XF zCPSKTY23t4XC(85e)oma=w$7c#s-NpJJkg$ViwhfT13!$Cr%qi1nJjbk6s&Ozp>AT zj!`MQ8aF$}Lj6Qy?hBLIT!#YJL^$u!fzs;Np0H;g9qdq*33+lZypNAtOgQJb71~g% zbV(e%93A)otYRiw?6cf8v1W z@1yP>FCtB+_=q+{PhM9p89Ua_ZyJn5qVw7k=3bWF`y=p(5Pp+YZAU%fxI!SDaTj^? zdLdl7Vwl?bw-DmY8XwPl#JbM(l~9E$nC=5o}##Hm~d=&8G@}QT>X`65ktRJP==cHZP5ryvD*H-l!K*{ud zc>Bi5RT5-hZ}uzFbqsYeog6DZiRLTx-mTM8uwEKXk}&toYI9+-M5;A;D2j-yjtbDIO+0 z5dq3nOqbrHI%)`<^-K1^=bTPt#lIX+jjF4A<% z&$m6LP5~|Q9%Q{XD7G*Ut9tFD;cJf$#MR!B)YC&4w`c1NJI(XGXVc@4Z8^m?Hj~#3 z&+a2f7($4ozR;H;Z0)c#S4-|)PY2qhnR>!7n7P4Z2%qJZtw`u(V3ajPzS5YPeSt(L zfkqel`CK_Xn4H>poYp7(o;5l7;L>wn%HeqT+U{8W!1F4(>^X4eJ(E{qsQCP^7Rn|5 zlQJaHIedS%ByyLi0QUz|-~qu$7`m#C0`gBwysFLEH|{}uk!Ws-#JaoaaC|Pu_oep5 zq2GrBxQ8Vz?E3ZQ?oEz=8I_<*1op7+$hxvOrgan8=Ski8OQA{hApsa;ri@#etpi1oE9Q{V&H#tSo>6Sv5U6*FQkI;%yUZRM% zt`kqU;7LuHQX#(CCe8wG!kz(CI5LQg<5N9rM2d9-Q~&5&bLa?tnt{++cj#ysK^R}3 z_ot245D1jA(#?efO9TF%5>)&nh8V`=;YGwkL-`d4qNG-`7oqV#1r z3QY=`jJQ-tc>Q8;9Za6@934914ohguj{bVDyBmUO9Ito}j^DK-uB2Rb1;x8()?giu zuGY%bA2&axkuz)EmYxNTh}~G7&e?0!v#+%;y^rhR8O(rzVuVhg%Z(klsn0Et1&_`LD+XpA2 zV&l5EMxu+}Zn<$n_F=!PxulaXGj9KRjb1IN_d1fTMxf)^*ChZI6iue6kC~|!4gEo6 zv$gW3q6TIhiyCQ)ED({RIkFp}9N4>d9VR^)9w36ztbNZyF&u{&TmXSFXk1H7=t#m` z2yDv9_H&i3jIxQ{D(3quIl-i)kEEYF;D7r#bz5MEW%;M0NuVZ~Ria7Sjj*mUCPR;} z^iXqMJa#yq_pY;LW=gH?AM2@S^>XGpE^AdIpfSDtdg;q6YTJ5H z>E(;+3Fo3;kj84L-iFR@qnu~C${aeqBjMFV=p3zscs*@lzKTqid%gMz^@Hs>o3YD* z9GCc2UJkyvSFml+9oWe&2e$AVIQuGJ0ScQ?iD|KJ3 zn-LVqBs9Z-#@}PV_jv=-5uOZb5`&&C^+u%=C}dA^A^9;&@6Z0KJH-h169c}l|GN*r zIl}VLwEHk~AwnNemLAf(Te;?An{7OM;tS{ubcgH4mdD-8Zb3Fd5WeoJ={#(9kKs7^ z+(&6srL8relN(^K(s%5lg(a+GuNTKEcj~s{pC=-3&5xQ-F19}k5!oiLZYRVSf455H zgZ|y}{5#kd(wKMg@mJd=&b>EY9p6UZ$j;3|k9lWhEYx%u*4|Da%7kMxKav)QDJ#7D zcnO|%Q7YrYa_`P}nAdXj--);2^@ zU|~732R@V=f%v;74a#)PP**7vnvJWs^$b3$L}mWN!6))CLfw9VFr0F{rPkCMI~E-w z6S_>|FWi-Qt0VbSI=TaS}M#_~*}S;^am`@8SfCzpB7fFzi&A zad>|dZ9;=KK~Ye#G48$`JeYd7i95{|93gLP78(fvtL|cEC;RNAKc$mw4cp&$bU*Pb zC)r#~<$k~>dF6{2_5opyI!>O|JyITfuS5M)FJe}(<*L67PIpGRSU4dUJxRpx(j^f< z#;r467MB~@!U5lU`01PB>67`yZzmJKMlJJzDe`V~LyO3F-2{ds6Wx9fZ&MLog69i7 zAbvx3d>;JpI|nj$m=C3h&Ud4nsGW!UlR2H z$JSdoMA>!y!U#hP3`2K^(x7yANGT=VA>G~GARyh{H6YS0A|VYUjYv1raW3xL=Q;2D zo$n8r+3Q++)n4&i^N;%LQmmHkgbIPC)T8NLR7iH6hD8rVb;~grenU(Va3Ea|(V{dV zSuiMHGSo;B^sydaEFzyZ0`iNaV8lZ2kGQxp-+d0_X`OWY01GE?e_-)? zj6K>(a^ISGhZR@K1v_^xj!q^c7JkE%bp~-A^{X1*^56B(DG0ao$&?o63DwtVKZ}}h zv2pVdBdt(qiKAZhJrZC-2$vL(p&R^v6@a&3hU_%pOpu!V1#8C^BMJ#f&N4S=?k6@< z7NU3^qT-&{QXA3DxJHI~>d#L7S|H>N_e- zU2P}F{Zr-@G#!3#FU^QMOGYied{p@`soQ#dDJqI+bm!q-$Yf>Ih!i()+fW5GJ{2mE z?tlpq;Eg7cuWv|S?r&tU+vO}9xS9Waa5-J`-NB{PKYp$(Tu>{#c$qdBzimiJKqio& z^!8HO=DLV=E2c0fzlJYI9Q`npfI>j_sJQK+ieM*=K7O04 ziS>YgUUS^YcgJPs6O%Hryk?f5+ELQ2{UFUtUlH}Wr0L@K6#NH6r8`b3$i9B=)1ND_ zlr4Kg5MosE`-z5I%f5@Y{%R3(sn`{uF!}%GKeSo**KwOK7Ikp8<}W!?xbNe#PTD@= z^^;9CoVAbSjd$D5scBD~wn4|6RQv5fQ`Hz#@Le3_yLtdd5%0OTmjSqpm{W+~6UIRH z8-0l-hKTozXRe zy>6-wJ2C}diaQn5P_gOSuQD!EUud?&oTaxZDcJrzew4<@DXEptFxt@SjU~yQr$=^McmHvI_ey*!fdFFnB>(kUIL0l07 z#Z>^k?^Q5lSL8>`H<6v28j)MNKhBWNCC;$cY~d`V^P7+`LB7ZmC0$9bQq~z?--r6h z^Do1N!Ab4>(MtCBF~Tj^zORM1C^pcU>?1h(wT#~!a15rI>|dWn{MQBWQh)P|z=OMu zfz2MJk27F}B-)PFW51=G>Fa10>*)>GEUAROW(APLFb(Wzhyh!uke(1EyLRLL1kTml z0)7V4AKw-)*2oJ(8(`y#&xwS9`22q^9<*6GledV?7(yF$3aNF(Sdmoa;V0ppweS7y^m=*eugw7+n)k`PS8hYyp+WXpc%30AL8I<8xFNl9%AXsM@tAN46J z?`kKl`#K9cFXQKYGq3!Fh4TFjlDnchZ;b2l6{Ba4lou}pn}e2pXZEJ~rrcZVsRqF& zksPl#qU#6K<}@guKVT>!0&Sb%PiZfHUD|ZZ7wIh#|7u#tFO&@SjeEy5I}5{=#s|D- z1j@hYOTAYosvTHXBH^J3{vyj)g8VRw!`q@y%9Hb&<`YAK@0w6Nck{8Vma7bQ8nI4O z<~>r8g!ola<91y3q-u8)PUD$+0)55nc*!#F8HLJ25NrBQ&!&QAU`rUc>C0X_B>a`W z{x|y_KCPmtRLK*!aqdk_B$6X_ow-w?*+{$Giynt4UiYE3WvQ*0iAbq!l__Pt52FOP zzU3_HdYK|6dk>C>Xsrk9nwA?kEHK0x|8Zr@!C!Q+`=bsZXqoU{o`Of6rPJ!L>#|9P zh@O=l1#j%o&?Qh_9d=z{=ut51AS4?Smx88~5FZ{3JV$d{T3EPOz7J9=@ON zjr;$&estB2XLlo%sI4DJJKF+3t#^8I(jh2cVISW(gpgaXdZJRsz$eSShyeYUYYj-B ze?Uh*VKT|2uUjbUAXdqe5eroze2?+B=JpjduW@_v6Iw6Z2G#Q(j6P3;kT#awzoCdt zm&k1wNNs(w2LF8+I*z~ND~_|AsZ8;b1734D$jpCo0>jG+9d~hg)flxBGel)vXRw0* z_m7AzwH(K@o!GUN9|L+hbGF@71LH1_Ds#`G!B@k1+(m+vGQc#p+xIOj;mX z6jMK6Qs~01>0fSsMTf4E{JDG8T6ZQ2qzpZ0iHs=+F-;=sq1DcW)-inkm?zYaNTmSW zy%Y-Bk37y*@f17TNKAp25XZL4!}rqBH*K|2iJ|k4zic{0S23Pi+<}3|yZQ15iC55X zFQ6~HmBWio^kzj|7{gVIk}*f_i*0>}Lwrjr2Orf&m=DkY}_;On@ z2UV{KAC49hqYt9%?aiI)6cKW{*Ljt<#Q=*6-FC8o9+t8wc|MXv z@A{S=<$Y+mUUD6aC<*82n>TuXz%f8*QpNH6j;}xZ-?&H(11fjq z%E~N9=`N?ho#togucj#OCPA8F=VTC1pW@)G)dC7K{0Hfa5qB_kj=Nnfyr8*S_R3eR zQQF16kg3e%o}8bIStR13L~jxEOe!;&H!!8-owPj*C0G^Hs$OKfOOZUkW|Ts6&I_@| z-DdwbvcZ9D$1q=1O zp##ej?1cCp$A5$WkS3eS9%F&;p31BF8xa&}L^)x!>Ll?^Nmt=`B9WK((XVtT}8y}krh}=KteYxZ*zQ*F75INzg*$|$j5;}F< zlUMXG3jVphQDST9-Rx}C#p3Nw7KwrGZz2b2jjZn>G^%1ZzaTVzBk}>J5zjGBVE@;I zkVz_zacXk~mO&FN=P(Og-@UA@&3<#f_1yhN%R$MVKkibFvaZKq`DuoFSCC&wStrCR z*XdboTQkC@$b1^Na0kJGmp)5bIEdkphHR3C;vcA}y@=#Gzr~5|4;eq1gNLgJI>08=m z4-=`Z?@u$f@qB;*m8&QFG4pI%jgY9uW88`^2pmL*+GVf5@7yRs9Km>pS@{uLt-UJa zEkKRRzsm4Ns#&xB`1t2`D7tb1ozUL9o$e*wf>M4-K1Qs~0-x!=y|@sDk`fZNp|k{;!6JbUOGmS z_MP@vL5m+(EH?{pttT4mWDx$9=`+DFMuJU)!rk)n?@Q%7m%E`t%yNrMnEeaFyvMk= zwog%_*Q?f$*4OQcV>S*1WSI|?uCi2nkeeXkeEV&hn<(MJBSM7REEho z_-FrIYaN4-7YujK8+Xow-)J4jc(c`w=SR^anVe3_&{{9j;^NT}KP3WaZ1qgJc$vXK z^pe7xZ)xdT{;z_PO`dUzMwE@K36<5BP@`&KwS*ZdL$DSNb>yNNF7wRZhi`*tbGdC5 zk4%9A7AOCdHPP3}ZARy}zY}Y$>uGNSI`fpbNp2!K3&t0XO(W`ib7*4psNcsu|C<&V zP)SNyn%4y7BZwhr@q{2__yr(4Q5S)ba!h(O<1u`{(>)+3?^ia6GO-Izpi;dcb^NQ+QF-*eL*P%; zC{*NH&x}#$NoiwvL}+LCg(f%gG@{D19Q3hTGvh-=|5YE*+lu4;thVjZN`BQfE~RMY z&~+HYLpjaF(qw(+kq=G$T~EaMQ1~4q^5(*3q40F{jpwp#q$mi0G2rqs6kAB{usA@a z>jOa)2+?Cu2a!xd>g9jI;s2}9$-l|~UkfAd4*?fUA_{y*@s5PkintQ0l`y8tpsX^+ z&I_yui!olcpzLx#jbq_PiOM62_n!;wF>BvnbpktLbaD}_=0h3wz)OO;qcucWKTZ^x zzJ=ocUqCuRW!FdqrCM7L1PogzG{x^W<(DhT4P~~fW{lXlyZTuXe^n_)(Ut<9jtV9KWrs;s0>I>1B9FhrajSR) z>&>p>dqGdG&%LAxGCq3pve?W9%$go3WHvsQNaz6=lo9+Jv>$&EoTK_mP)ul^6Zw86 zG-PI{_sN2!{NuDAsP(No>sS{|J;pYi(+6eVV)B3Tiwt8aT`D? zHk;vfTfDS^AG595El`?l;)!jCGG#B{k!zA?k`e!!@SY<(7(!<~P#;ghm-GZQ{^yRW z2rLl5$eW-nXw#cq)o5*-NIBQqI6LWwIpfDKOwCV?V%{b!WbIakkm zUNATOa1q}8za|R)#e(No|Jo8ntk+Hvcv+gSPW-F4KRzz*%8z?mlvcV(wmKj}BAir( zMGR06M7=$3BsczG)Rv~azik60j;4=hOj%)wM=Kav{yiL$SJKN!7`w_5G}JPID6lvK za$KFm2?=!&_+`RSmieDU(-*#+NW5BK$I(^Y^Ygn>+4Z}lQx97a23$#oxBt6T-U@lj zeBI=DuYEyFWLU7Q{m*gQ3yl9PFCIXlPBshO#k-RbYS@P(}wM4<{a5$#p7 zKK>BuiD&xW36Rha?b0V4xYLUN#ub6dBklV`I+m~l7BcE$(^b3kvDajki|!y{_ro3N zo~J?QYvyhV#y}9@DS~hIecsuN#IUL#tnXN7&Uc+T&*rm=nL0m3So*;Nx}HEv>t7c| zM_GW~AfW5S^wAe%w%`w!kMTFHPal4!)Vz$slY{&3(IWzD#@Y`wD44Y`^L{Q z&Q>M-SBnC{%0{M^RkA22wgx=N?VoUOP$qtDx}`d(ZG8Qzu5$Sw3)67AjpWI{&+T5D z>GX3={ZMFkz7E;fMdGJu4u|HWX4{C=%LEmy-Nv(gAxi?-*Qu|WTd!J@P8*4zuGpaA zK~eM7T`p5?-EUy%K@C{S0}^!|=R}jP<%$!ZXqln9(cD_g!H;DDFVvJ(8s~fgV7Vk% zUh4`*w1_}bJ-kU5R>18daE-z%9}Dhk2f$}gicIOoSZ_{eX-EsqH>SKN0vg9%ikm#0 zW_^<%4NbDiZ{u%rHx&%X0L}|fTW?9V{SeOKCKsf;*Uv~?=%tIWsTo_2x3h7{2E?uP zFAKCqUx~Z@d{uyC=LD7kQ`MoRbH#%V1Gm;f{-B`XueX&*l1z|8*)*s}O0*LHuW{AT z|9K&u;i}v$k#;wGOS$W6ynQdj3)j48@0#&wm=sW4+6s>fI2-{sSm?zGwBG!3Fmsxl60w-92}YtV{S{l|bd zocfd1xQ1@)f7Hx96u3as)b9JPb06>Lzn;r)d(zluttsGK`@fGho;ye0ZXD5g5_jK= zWf$c_COyy4`oH2nfGSV8^jajUcc`Qu_nxoMcbrLH&lY0LqOVc(l!f-k3~K$aK}`AV z)-J6RU}Mw(ggUKljh|6?OH{F*9B?2s_r4a7Y^u)bQPC9<0w7De=|j;EHmpo~1c>z% z{Y@Wp6~GHwS)QQmA9-$6tjNk*w@UWI;`JGTxTQ2C zlXobZHkLk|FdIoPkhL zJ(1i}#OV&rDroe~%4a@aT3cSGN=k>LVra0ZCsLX6+}_A7)e{xy$(gg-sCiPXV!wVd zxOl+w1#3lBaE5Lp z1w7}KK<$2D#9{8$Y6@z4JtY^pq!3ScUVwVXdSY&7A5lnKXpm;7(y$LJ2uj&7$ zD9Dmmqg*$M_oBwVZnD)>a%`--V@=6A31hl+&$W5uH8j4o`o(quRH#f!n{6PQJZMNO zw)v(0_!$~#BA}hE5ad5}XywChJ!}|=@ur{uCmPOh6s|2&<#$k6Km^yNL+odQpg3Sg z*i0N9)bn5Vc)hR{p-ae7H!fO)(9`Y03eR<6!Zqhgfw)BB#ZBv*&&p)x!o8TLQY%}L z@_Yq-6-D{1MpNK!#^@rl?&Kp2O90k@S%z*K!pea4USOoP);6kamN>&uj&)F--a$nJ zwNw&VsND~I=v;@tF!zHMh4yC@Xx$z98dF@Z3fPVc{*Taz3*|4RfWK&>eiWy-Tz)&3 z**1waBW`Z2f~lDKeOT;Er?*&@7(mU}vwXb@fD%{H@aGq6@Aj!8o+~5=w2ElE zqJerSkG_8>pr>l1a=6N`x*|Jt*7tUMP9+^H~Gm^Do87{v^=}&pwYBQb0tuhC+@XzO%`$OGR)+5GTkC1#ffA*>Hq=*YW35T&(E# zzR*@1x58!ixg$aY1<`5$0=ph90`vbl{}Qf`FtNetX=2dBob^z zO{+UJh)uF>;*q)HSYoCv3dNp5u%i3yEj$!sL{9_h0LvURQxIrzS~=;Xba z9tQe{KMdr&Vr*{=fNpyVS1ShuPucylf=e#_{wKwLF8s#3P)JZ&J+E)_p}c<_C6&<0 z31hP;dj!zulaO{cAuzDf$Fd(G1Y)QY9fN{qj*5ma-^OjJyVWj<2}7ROpmiqOF`0cJ zS4&t4u33A!kr1qFlxeb|MkPN+$Eidg?5%wOUDKHOlbdzXZDNqvk$|`-d?a=L{ICLCfE_--8y#AqC9aI#w&_nRtlRex6 z>`J|jfMT6!m5ME^?+YjKhXW~j$OT?3newl-#ga^axBd%>?yaABZ*dUV%uWj?^it6z zhYdp6g}EZ6CQ~i(#Z5?L?HqQ*$ar_&yo#r8{bYyb)COggQr)vJ9{$oYh`H zKq-Mj3({o24Y#@Em)K~4n@18fUL%pmw^nAS)1c zQAkCxLr@9;7|eedf$?J%8YW*PSl&NOfqBBI7M;Gi%Yd13&-O?87I~ZmO}6&z8hB2z z#yzOO@1stSpCKWTeR3;;2&3x-4ShpR&eQ;4J5fI1xZd~@#U?DRP44Z}NOXpma-#%> zT`btLC!W4(Qxrui3bhP!{iZc!?6X?=B#zQ$Qxt*xNS?Fh2z2_G?}E%gUkYJ?yjOqF z=}gI0_NykzLnO33i2{VP@cw!0j{8!wM0iQ(>Fb9PJXv@~hU##LjDQd*v7Q*O{1wkh zJAj&*r_{-|@gnBA#Fy`(4P*VmgHfAiYn%uA9AlTCv7M2C$Tk*#lNmU@xhx4d9qs9K z@v8%ZNf_hAX~nv9YF^+U3rkpTR1zNY%jI$p4xwDPiW|?M$E|^fy_R?v+3{-WRcY6I zJUs)#wf>ztC^Ma(`4>>)JJQiSnn_Mi{Xj}pm96E}3Bm6uuc)eQv9V(Wx8cY58ZNK; z`+`DRRS6_x%drmN+Tqy)0$BDb%Mut$4*enNN|X_3Bg?~gIm^!!sjpGe;JA%P72gas z*6948w$jpOVsQv7sy+vEhqb8zc_onUmBxwn<2XQ5o8T#7&Gcqrjzhm{G*k!o^B0h6 zG5bq(AI7W(P!LR#_UL<&wBk7D`YUg@5l=}lx_%(O4YBoe-PzgkV;zG#qxKE4eLV4O zq~BR|c61F^)YG2tJB`Jk)K$&ssCMK?4B{Z6d~rq#E9Dfa_bge70Fc)&uBjWQ4;?s$8^X*nYFs z#l9L{6tB@2F>r`Su9@itn%D?YB^I;TZ{d)nIr0}tY?FQ(!PnF=prGyEM+%9%745)- zX6+dnN-dXhPoZtQBx#k~1Pi^-`Qx&H8F@u#8TOL(?RrVS#Cb>`BpcW((9S-_U$6*O zNV!`01(8f)*6iJW!Ov`~45*E)n%bYvH`tf6&UQmG^(ch1b1gU#KKXZ$1;2+lsOn$Qz4`TmMUR` z6ZhR9Rwkg6H{}nc3_I>ZM_|>==_gMTBp#^U^UwU0nZl5$i9d?^48Yqb;pZg7^difc zl{%ppmvsQWC(Ho4|3s5eo^V-3jt##07VQ=iG_7k-6N<{o&-{Z+;F@kS%9GRvv7O`US0g~E=(nXw~={q z4?k9}Jc~NxZjBxt`^8xiVFBuOL{ zdBy3~2pu=HHB($)5aR+zO=I3Y2C8*GDoVdm58KCkV*^}EKbk|z6sxl?m~UW0t7ZAg zJTy>QA--h}O{6lsAQCg}&c--&0~0sDM!KYAk5Mmunff^c%<2HPT|=SCyi3rWqCf!_ z*BcfkKiz+Sz#O`WO;o1(Td|xbN^MaGL^9K7J@_q@6}Zxw;HoDt{Si<9=tl^FY(4K& z8jI3l)y}+1MEZE%JBE^eWCcug(No?+prG)k#XB-6k>V6>UiF|r33Y)5OiOxf&-oTT zSdv3Q2_SqLSN`fw1~rdDH)!ZZ96i+t&l5AaKFU)LoHEl$di3Q`M^NB&l3Y^djF8jN z(Awk&-HWbe0RvqHtcLd^!`5|33!hj}+Es$SlAfZ4$!pR)nR^Ja(a{1fPi0ZKptYE5 z9?klis3z(DFd|?rU?m>tz!638AH^wmjtf;|-dJqAeo90gF~n5e3@JMvCSVb7>COlh zk_HQweXsed)$|4`hyeP~eJvj_r(ejcI>re>`G~T+6!qxRP<@ip)i)}C@x0{uulMM^ zh-8VM%0tGVr&2ma6~1@T(#C%}2@Rr6sjf*V)*nKnPszUDr#&i6t^4^BJD(YaK+7VA zJ#aHDRTD=%O$_%Ln7_`l$7~#~hvJR4R+R(ACzd-qogfDcl+s7l!YngdFfB_v_n+uY z^$+4XO?fX>lwgYTcesD8pq1ATDJ$<|;ObveQ6YYOq!W(iVb(>8o;ROrsiY$1>5pTH zY1t#{M*;8qDMmIE&IxyR4dE+QGPImIWt6#0;5&#hQneul;RZesMr5jI2MF#>!;|IA z#u!B70)Ec`H4hbd{@}`pOd45LdjQ6t$OtO!r+oCd8ZSvn6s$Bd+h=quuPH`j*)qR6 zUE>nE+>2aeI~avqBURBF!i&Dy5PqX5AQ8!>V|n7OS^~I509hI31Cfgwj7q-6Mh(97 zbr%7v+C#J}kuDGs>MkA0lolTh02cKdnvVUi%e+7zMUooP1}vB~-<@A9_GrSAIfbga z1})A^EJfajDs~5h4bOtn0J_Sk);DQ(Y!k>6AOgWg_m^ouqL8Erfdw7FVhO^$ENH$T zc4Jzc!q3bVEJS{4AUN|`J_SoQ&usJjX~g+Q{O-h7u82Q(3oqxr48$Gz$+Bzry<$?V z{bR~trGWzh z>}bqn-VZgPH}6G9eiaFQodN~Rdp8U>4gx-dR4lysKIuuDh_vTJA|fz?F(yMHvan)S z528?2J+`gO{Cm|h8L1iS5OH1&S`@67UsUYy)ICqC!8U>P9b084hl(vQq`i(ANQ(Z$ z&RzUuUgB|(VkkuT>!}NOnIi15+^0{lUxiMmsJd_w%Jp<{c;Hz#@_mNkLe;z0i-HE- zT|uJg;O35LZN+UmS(|k)^|RQZRmMSWCm(8Rgz^s$ zoQkVW^W~jGvy~}jT|LNrRak(=B1>qsEPcx}aZ?G)s@$Dh664_L)QrijLQuEf_&%0+ zHhnCMTZ~RtJ+&vIR<}^db=<&$0w!=!5UzOJjnEUK^}9r0VuS91*k~bQy@DzIg=2H= z9M_1w&QZ@%&h339_tsr(v_85=BnFZXMMB1FZ?_O_rJ}+z8ZDV$g-u|Z!$sp(Nx`l3 znSzq^avf6}mv&BXxMq5?TZqG#wTMK?6N*n1U0Z;kcWE-Ms491)@H@Uef8 zjR&p$6R;)P^-b^^Y9%bGyvQZ-nN=JfgB{jA3nj6ogOU;d$^03;bkIsl(i1P`zbk() z)LPV2U2_`Ry9+>XCgB+&I>2qLy(M^_SkY2JNRzlmmV|@UKTWCB@|+~8s~tyPHH6_j~?S8H!HfM<=BaD;aJd(3 zt?RKpw@Ko%G&gsK0d>PznvbYSNgjtD4{6A0SZM@l6h31C_U0~boALA$p9DzsHY+q4 ztAM;aa7ce|lqseIi|#t~CT-76>rl2zR<-b-w8zucX_4%Id;l*kZ-2Ncv(nK{y~o0q z7FQfW7(pIEAHf>I@m|haT4g<`_-oX*LO@vn^$l-tF`Zrj~mhx{SWh zuLJVhhGHy~Fb&#}Bcyifk#rQdW<1n_7iwikWgHVq2Y}-O+S2q=JqIEsc23ACrt-w5 zc4j!vEN`&7rbf(2tS(^HubfBmGumn*%vn}sbN%i~eAyjQF?{{_g%&n&vg1?fp65O_ z008z^)H&1a$A!(&04x5m)Pna9pxqU!zBW}-y^|dicP=e$;WbKw62R^l`M);xk-Q-^ z(I2s$RU5|{A>eYSHzVJX*TGvG{7k(EmodYfIr#b@?~-k4Y8$OJujgQzYU!su-9IX< zOW?SjAO27%6^&2u``54YZ$m>7{xNX2Qg7FL=ol;HOz=)&Tp%V$ow4rb>j?Ug{R?>t zyeIc077G{#*T}D*J+dC$dt`4+_XT0CX5oI}_xft`D-WG1%i7Q!>0h;lrRFsyxAc$F zJc_!~OQm=!UG|z&Lw6$E!Nnw2IgmI0HcT^5FD5~UgUlMQkRHzuHyzWp-`+oUWe6d# zuKJ(XGi-hzp|SKxN^)V`vcs@1;v!irrpa+FW3!l{r8!wVzB?v85j@d7@%eWR;I(e| zUH7$Q8e1BVCQti|mb?$00xaYFX`N#u`JXc%Qg3*KlMXFinwmjP%I=?K7-I;od0JTW z-#40<{{H>j&uiW&+*XrTC9>$Zpq_5RN_Oj)5UJPSswKG$%g#NCFbNMg)4u6+SJly9ZB}`D!Jx@xKRP%*Y@BW8XM#7 z78*9yXrgS)&CFhJ>}-TtzE6B}jJW^0p>USSo!=YlZ46_tEM){IFwUETYV_)``U}*_ zIkFj)EntUA_S#9 zI$EQLV<9ZCbwO&>U)f2AZO7UUH=#+PWZ;X^u)rgqDj5`u}Ss zymJhf4V59k6HzRUIDx^=cSPY7ejXI85jHQ^&S}PR+$noW2*_sWE=X+E*2_Gq^TaVrtsTKfe#}T&idGXB0&wj7G>0B5)dF#|SY3{bO^k=F)Ovc=X)q zfuH~Qi#^S<0WOPp!fP__@a0=8g!|K5e6Nc{)SBj5y!9W-S=PZnMlXyB?9}RT4LO+c zpXDq5Yh@4Z!aYN-)n<$u%7<%M$V-(7I+eb}`$`0N8f-bA)E_Gtp&oGf$jKgxIK6m% zaQ~XjbCyx_x_A3Y99kVM`MlPwRU|>j0Gq(mVQc7=>nFgyf+o;P03}dU6FvW zfl|7BmMH1L>>P{!x>%!f`5&h1Y3CcXn-81#WVAt_zpx&|!g#jp#x6Q(?&3P=9ZDhJ z6MsZM`Ia;WpF=}oBmEP>@{x;C@?w0=PK8@ceK456%bscDCgL#jx>Nxix-P6dnjgpG zD_RQO*{XO)NcL3pqvqjpCnu1|l9%ilI-4Pez@liMoM;me&nY3s5#GF3e8E^m!f+@4 zg>BRo^%HFUFiIx=CXhT!TeQ)it>ClFh)a`D%EJF>E-l5Q+@tW4=-lUngi-%S{*C%O zTF9S0m%Wy~%Ogk4bnp9eNe7Y!8qIOmxQ4TB(ZuzdFf}4N#=Q?Q_~vyngIyy zh?98%m}DxY6m#D&_;H;|6>(FjLe@0>Q$Urc0Wj~|7+Y4i)JJ|bX!qqm-FzoWJ(pkvx;j-L=6UHL62dB_Ov(gyS*e>|w(v;IQ z(+mWCU!IhGQdZrt=yZ=HI&Lb?{K8#OZXKn!Lv41k>T{#4WT2@NGV>2zcUz=iBomFk ze`0yT#dXG+Q#%_NfXtfsR^XqY06w6rJt^IxGE-MYwlwDbF9==aP^o!!3B}{0hQ;Cm zxvfv9FlhQ=#s4nW*}iwd9qKy%$|x#H#93(saC)_XoDEEsqW#Pf$ha`oppgI>GFFzY z-bB=7-n22K)T@bn#?JA18T&lKSzk{{gC#X=ZcyX2MFUf#D z=haUz)jLh&|69M`r>DK1CGm+rX%>RM4P2MIj;s^LXWDcjyisnSnAXl40g|qH2EtOK zWTTLPheJw2Qj#-0fh4!Hv$OY!AZjQOvWbL5g?mK4DD?cK8t%2kb=9;>sl7RkXV|WN zu)^?iTqS`Jz{oJA6}Mp1eJ}f2Q9DP)JFbHIg0=_tr+2XldKzE-f(-udBhu%|JN98$vCL6qD$V-t{sO6Wl_zpRbYQ{Elyfeu4Zw8E7!=BxL|2pJ4 z)N^o(o{2PUV_7Bl~e0&}00(zmX7tIivKc27< zDWE$4kg#OC=PFX8ci%2{u(uU!zlB3L1uMQJ4c%+kQ-6m4+`FKudTx(5hn}=$m=C(e zC#cArH<(YE@%dZuQ|$< zGk0FhQWsRNolaG5)*I^~XBYO178H0kOFQxew#Lf1_Koa%R-y8*F z311o9k;_Emvy5p3Z7b46AiY?2xLOOR7@jgUGdn1rZvXui)vbX`yePIwKf=bCQ6peR5k4CtUh5(n0RlZNXsrwlby3YfM$~ zi}wnVHf_fj2cc1xc}XB-T%4IRW$5Lye;UUVyZ!Gt-v7gif7Hje0b6xr|14JgBpgGa zMYup!0bOsWU{nbCK~#q9BDwOQw*q(wMux@2JTG>1B3FmEXkABY4&Sc*#G>O@ez^65 zV>)OH11SYsIeb|)+$DO?yus>G_p01G8rMM6itX+Dhr#a=Oi;XXWV{xTlIyoI&JUV9 zy(J6y{&T@IgR-@B%=_S;x0r&1AwNfhBqN&0I9_srPN_8t|zm5BO|$F8Gq0u4TZbdgOD2W$e7%l# zyH059zLm_}cv~gj?rEvLL9Inzw*F>b_V0|^*p9;nJ%ochBw>YgxzfGSuSfb;l{5)3 zDZ{m(p9M?)=MxkD)<-Jc>a~93fo?=ShYRBaS_w9qqQ1GYU2}v`#iN;@zk1GQ#(SJP zUg1kE69_73sKK@C8+2uVlDl2lU6Fv|-G9(wtBse}d2!m*GQOAe;kFk3UV*dM>y^JA z_MeQ-UbHHzs%RdwTKZ^CQIB{Z!H#$*4 zV)_Vd*I^NUFtv4g0)^(zb6ZV{kbFRrnqnoegw84C`vrTXLbEs2?x{S+qN#=pXT zm%?>)+=pd9_>+`}F)`@~BDBU~Idtfj5{S!~Ch!UWnQ$sg_Lx@Uc`ww76A`}*=)vxh zlosecxpRrYs^#xcAqxy?72KV}FY7*f z;5aYku|lgd4q9%^jmB;t!DIiyGYGF!1$7l>s1ty6|=Q+h;Wobf_Yp7UV(?qc3;acac+n$eQQeE<=d#Hz;1Xb58w^8tj7WIW0c?!H>CZjm z5LvgT$68lQ*2UqTf(n51%@qLs^V>A1vRMj@3Ri zhvw2$%Vg_2u>LR#lrYGGvJerH$YkE%yGKYYeM&5h6|>F<=~iOULjc!{S+Y9^1p@(ZSqsiILX9N!71dbFIrvOv$OdEl839%Gnd**U)D zdNN9zDA7R#mR~K?i3Xiip;oqVPo}k&q)D@}Ja?E@4xM&iM*47jSX;ySeEilXg+`gZ zvtroG<`9YBCZ@6Kx2C*Wn=BB7Hz7Xe*K|3FeT+~$Se$@bP0@H#tiyvej=|!rVa}ft zSrTA#)E4hV|C?^uf-4@*FR7r!4WziU%t(ab$5T zooM>cD23HR$$`t+HI1IHvWB$DKMZR*Yf_DqGPy3G(6b7OlzSMF;2?H>nb$Tz7TNrzKG@Yo?l#oiXjdyjCt4kWm9xT0=IlKl{3QTF z*KYS!NWl^qw>I}z5XglqbGfZ3P-2_+MZ+)ZX*LDzp4QDT+{YJ-o=GkMNkiRY~8{;sB8YU8Od(1%s6{O&~*ok{6_dXFQ-Uc?O2L@tI>E ztRUbpeoa!J-U+Rcq>wT5&A+7p;JT}M;lzV8Z}s6Lb#ALp9HHMT$qzXRk{?dc=@NqC z5>bjme$BE7luhlSTXsFGcdq>@5m}JQz*;yp$Xal|)#bhvPe=0nA;<2~=gT3(k#_?p zarFDnG)!rrzgFSzWvkAgC)VnTGZNMU(YJ{o!Vd+5s+VZT-)ELJ@@dj5_2Q2ne#w%mtVV^&9Y5btEDp5_6T* zU9F>5mmpkl&_cZf|2YU_552Ux(CXk;J&Yq+}_H%42ml&_L}nUFPGlN0DggKefC zp+&jS!>V=8?VTHEa$^79+6H^iK`&a8(lf%y`%y&{PDYNBPxmxvgad#rX~!n)qg~r% zz%2f#w|RaPxH7S_&{L;8s;!uN-x^s`Jx{ty(1ka7D`HzD*63eKLeE_I*x4L#;l^YX^|GsNa(>ai`}6dBR8hG5O_PL}zv9G!4_{uUDg>L&XTi($AjSJE z5*78((Zv)?b1(Mj zes-7rCG7EWap%J2v&82C8odDTgWvK7&=uiB7e<}fp61y{RTC#>yvq6)75)iKibcQ1 z1#t^GN+E${jpT**>1GVL3^j~SBlfF*iZjWql* zKY+$=u7BRp`T{?%nh^o}vT84Gpv#0!<-Yx7whb1xM`v+YqhwWx4YcEFHIRa+7idHw4L`u|kR+yYVSv};f?(wSjWjP|$Dx7T>R}!LZg427n zB5#>eadUflGyNLr+mI!*`L!`WVIh4&a>9b&H$dw$iWIh6DLj=O8g*4QNr4rg?5K>_PAMjhmLe&SaXMC- z4?Y&&YVYy(9*eST+p9uTvrG4bFG&x|v_5MTe{)Q+Z2^#evv=?mZiO|{rT;WtU9qZN z4A53EGFRCkWT?IsH#1PwG;tHQUGjFkS#u){tPbOX{rlQyJcbudshYL(Izj+q877j@F&fOl2@R7qqiM!`6b zpz8rD?gHY>5K0%;2R++MV@dcIgk#GQ}N zrk)b?tg6po@a3}ix;kpahWQW%tt309C8?FlJCtL?Xfl)%oaMVj>6bl?ogNG+<^5pe z+WRX8z2gVSjZ9bi^zRg(4;(&m&H4wkJZ|vcz&kP+${2Gg|G7J=geYQCaWfnS-jEoE z>HF;3xS|3tr9HXpaRst(^0(&&4a&k!x*LoJUp_Y9GtAB4JLuSPr?A~6S~!}_vA*0n z5v4Sc8xQwDd%1HKQR&my5HI3Fzx?H$PNV}CeqlC^j3t#C-Y~s?KF9z^^IAReKUeWv z|4)sA4QL~{@#P8+l67+m-{dRL4FZ_{@0`z?$`4D4c2JqTa0+hzan)fTXCmc-39I&Z zl7Y5%xAQYR`G6N9Rc4&v_=KJ)S^Qydt^NK5Vn9|&-6|De`f!my52G%>ZW@iS5jIj zMY>B^6r@`^1u5xX8kSfZBoqW`0g;kM8ib`6k#6Z`k?vY@so#hD>+?MK|HXe_&c67} zoHKLgoa?$~roW==8O8ZRC^H}Q5G(o1y(mczO$M8>V2O<#08f47)0XoVlIgxi53Hwe4e}2l)VyQxlFV z=p7Bva=_HQp`G2hKEyNpU%ai%2jcBQ5XX?TJcYK|~tnBM~C;!VX_6xh^@GRCvUYx1(9!)(ApDjoKOt z;&X}NoN7p5&GEGs9MagjDK&^KeSHCFK--Ql;qE7@8^8hPE)peohec_oN7Ddu3TfJ9 zCkUs1mLxK^o$!b3X=DCR>7@OZ!+oi*)+{V0CGsR2kGsn!v36jg`d5^T-dY8_#=kl~ zlSP6J$y8b_G&~u^5H`UrO(f~d1)zd;xXCgx$+t%esmi^D2v7UMi%7ScM4NK3_3s;W zcpmS>0@X zxYkXMbIg~h_{%-q&#jp8tz{R;!s^>mE#Vb!j$1SFmeQ<_s1~ZaaqX*`IM%GAJPD1> zcL7>Q#|c`e7fi_&L00x%1Cy7X%N>sm&mz=CrpNc=!}dJ$-%JIpv7?MPe}XT#il!=! z8cz~MCsLu&0q;3*=NT$?`V{}|G5(#)bY%yxO5{13c+*qr6y-TS_2fFPXukD8*jLu! zZXdT4#`&1Q-9^QX3(Ua!87zLeSs3txRQnWbacER6n0#4wHeON*7HbvES{UHQAN^Nqb z6zG7w9@-QrhW*y%6c`d)wRI2qS{q^kN$Pk0PNz z8vRFHQB~iL0#9?eVi%07GssKkR-T4fTJn+q@Ow`E>E$DZ2Yx>_j&f_TyADizN6Wsy zq1x=#CB-;h@WRQBXQlPr)77+9_BmPXDZENHL9#S?YN?uhjhvVpcNDL0P-a zcVNQ{f=G3tg*fu5fDT68{6p>WRw>Ha?>ZpW12CsTh43>=b(82FrUT z_D@J?b417=5SsPMtq2B~#GV7lv<&MnCkdWB6x#RgREd#Xlk_r4;8dFM)DQReaBueo zUuBzlnC8rTg7cee1(qYDW+}vQk27d&Gj2$(8k4w0SHkfbG)n5l-|C{%4llRa^Gx>3 zk9)PkA_FjfdDL9b=btWS>uMbJ%jD_Nc)36*fKINjM{fg3M;^6^pGS>wzqgT@K|zku zg<}%Pct^qH$i~^9diYcjmgy!(XR_IyoF<^G{C&g4M5f6Ixi0Kv=I7naZxlp-b&V5t zl@eyox2DB#U~2FDnkVD@5O@6xDu@mj+K`Dm@B8@!xBG`(xYL$?MyS$w1AlZKJw% z?HIs&2Exi8=`bwrL3f@_qCI#w74%RaW-C%UvqT~v$PouT8SddeVt`j87|iojJkU{+ zir%^Yq-F1J%0*!INC5>{=N2xLo-D_WD{kgeS$d%j!r$gnc73?a_Dx}M{nz_s9Uaxk zkhAaSQx<6J)R3U+Hc(nq`0J&?c5x{Uzh0cd?L20!F{b%M1WR`R^pwz&ETXv?niEko zIB*H1kE#ex;e*Vr3}i`al_H7%#Z7$yCnDOw89Hw7cDczaG=e@y4SE6~NgX!*-(^e% z$(ev{Z1b6eXCsf%lC=-j6>3Hk{4EU0>bb}1d*LDgls^1XOhLV0Z>uHui#hF|=8-$i>Lj5Qv!%A?}NiLmz^?fo&d z9X$1kpmQFL(K29k`oUfJE^5!9>pGpbX}xIDdeg$6YLk=S$vqE8?k}S7=!=*jf|=i8 z>53tmx{+h!n=TN+0#UciU09wUw-4ttMR7{mUH3GCi_;t_1Qx@FU4gy1^na$bxc`{( zqr&*$pQhblrXY~J;Gkab_9)zV$ll8aBIW)L;%HRvD^QWx<^A>}VYSfj8;lG_fC}88 z60?Srvl>!OquDkROJuS`;slx{_o*9@ktUm^vfJpx+jPflp9AFLXSbvpV`!O(|Wd`*kZ%?!n{a3f+BYOXnJuu9%79voWwr-Uzq$>)G=9Uw3=N!rMe!EqE13!gCH}601&@nm#=2WuQ#!iAy6>Jqy)y)4irMyvKRt zl9B!cxhr6_8T{YmGaqsJUfE$Pt-fqT$?;&&6+E>UDSih1xa|8mV7B*HD<{6WSz~$X z7P;kn=Ee;Z(Cvy{>Oja|=FWf8nfQ*5GONBM+9Oy2=}f_y;AH5G6Io{p9}5=-c1yB? zWXpL_?#G2S%lBW2at5CG%F-RnuJ=)n4SEi0!}q}p-%QQhGZM0FMz*`d}y-_mv0oqVFOzf8I`T!iK47dd6ox+T!X8w=>TJ6Odrla%&< zD3!0~f{GaMLBw;#-V=%XW0ZMYl(U>A)_9hlwe7dtK~eTxLGCZUxk0SZm!ts+45F4HgJ|rtE)M)N~aXOt2 zopa&Rc7WhgJK~rxIf@`A+cgY#B3@%F>&Rw}4pjJc;Btt=f4nLoqmEk^H+^ir^#xic zjt$VtSx=&b5+6AD&a!e>nmy@f-b?$aW9fJW`e8xoQ4^+ zX8dySZy5*Tb6&VYzl$YGbfwFV>g*c|u8Ab(bS=*4*iBd?EMA2+K@+J6Kmi;RbCY0mNwlcPguvOf&;eB;|RFhEvu1huWXd~4o1d)IC6 zsbH?(>UB$!u6}wRdNZX{R4U$h=7F0#`S?b$h1{tC5vfFNSW_bth8@Q9RM3~e=&Dt{ zdUAB{>UKjSLAV9}?oJlrHc770Q-;f-!;lByE4ve6A!d-9IK{w~?hBM~`4G#X;!}Rl zQgL3}o)6~0J#z}^LDdCz1|jP$lVt(uG#QKk%3TfV-bYs9WNuyMp<^EyXdTX$SG#r7 z%^bE+9^Ws?Qvmti~v-+GVp@fNGn-@8^{5oU_ZT1@_pwTq6I&Y*9~`) z8RMnzqQ2@v%rkUKPh;;lBH5Bee@hi2sED z3jgFRz*AoPDg`eI^?H6mX@yZ>T^ZGTNpvFfeUbCNo8&jEb2(#6j^J=;$nvz1lCi_6 zcliHeRt^ymvwG#Cp1xe(Ri~&U&ygYzyXkO}qBBCnW4aX0@~Ro7k$*OIajo^9OV9x? z-5x%6hBFSZvr%U_I$e?7^d)I-nmB6AmQ6MzvuKKwBn&bQIjTAoaAduTM7A%McJQ~E=c!)Y2kxa`)QB3;<}5kUsBaT~6h z+j_so4HP(azTDJEf3;eGi#jZhNLR@QFB9l;pYkBL?4&oZwK8z(|lPa zw{+=S-d&n=UeUahN;Nu51KPlU(zoV}yHX8c*HMS31^9+&AGvf090WL2SwySZf>INl z4=Kl@dZEC(fBYv6c(>cmM_%=Yq<>?C& zA4XNu>zq%;QuvzE`J47GF8=_}sQn1MJZ@TO03~_!8kXB#&E%hL?P}=2+56tA83%E9 zA>?na1ZVWGVO&y!;6>O%jeYE7uQ<;XIdfcuD)3k~p4ZcFrR9jk%`Y9rMn9Q(K?ryT zo2kDFuG4%~$eii9_kT zO55Lvg_&cHnK-_SQcaT-Mcu(7ofc=33%j~TW!v*Y4m`VlW^9R~$L|`i#I_41HT%7H zD3dpAMD}#WtDc5MK^ods^|jj*>I|0#zg9%B4u82`hkmW7V*7bQ6GZc&((QB8Kiq;p zvCmy~hsi8F<4PZ2=m01klk!zlX?ibXi4Ptsxbqpbi_8_`a|N|y;DCdgyR9Rq(PEB6 zI~o*;F!m}jODDyATL(AQ_um#|mc55G9ye*wY~t4_XLotfIzHx(vCrD8DV}Vj8AU@j zKEi+S?B|)@^ycn!u*DKvU*CwusItrSgK*s9T?aU+E5y>&z%jP$$R`Rjz7Lnwl29ZA zv&3MH#`97cqi!Y><7y@Sg3sl2e{5_yEyw2Q7B!IDBJnZ=YLS$qhb)Y{;Hx+Nv9&I$ zi%3ZPTQMeyUI-@M*3p^o9lK!9PBeXo7H|SZGt_{$kc}hTXtco2UL{UG7E7k#N8bYE zqN9xOLq|czhC-wL=~)@ySEYB3EeBK_mj~!Y=k^w>xX?-NnU`Sx-MV!`|NJ=4Ol;*$ zAL+B6wbRH!&phN3%sT4(afg`}+%gXO14*Fp9u(UVyKZZs#;cpLyPmEni+vplHFSFq zTyZF0%V}sU`CpP}GkDS{dpWOT5WO^rmS50l$u$J1%Xx<>V3#>)wU-ukHUoniM@w*h>BLh%5?YYLJp#q^~Af%Q{Z>h$(}77Yi_XvMLZ>)}*n zjzH@r(guq>+wXbtww6_^RWGF3I4||HHaKxf8XMhZ4A6nRznuA+dzm8e!13^;rOJem zGn!a38d@Y;cD&K(Z_@X~Heq4gFcC3G!WJ1R z*I2?2U&P6u4|yHU-UqcnqTx9mWYw1;bx+xO)SDK)bizcx&5P^`*_J@kU>jBIpDhRt z7%DZ}*Eb=^+JRw-F1_>Fc!dYmTpzsvD%7@fi)-w3+;5k-3sVlbHNO=?w_C);?0#G0 z-0)v|a9NExG~y|Zl57~w6TWyu(T`BlJlYa2kt^dlub&cr7E7L7CG7vHrpzYEV@Ba2 zobx+3`Fe|gh&|T@)ROD=5Djh6w!}fT(Ty6D!op|OtIwZge5q|^{vdefZ3ios__g>C zrVi*7zlS|k)GIn&09MDb%LAsG-!PW2Az^baaWmBib6`Bgvgl1$^N7{=5#dEr1#e8K zxNp!1|@V=DvZOMx5o#tt1c55nd$z+2ueO}F1DjH$tSW&KRb#h<_E(8p` zI_n5~eB?Odn`U2zP8j*^5ml0;bYr@O(>O^M+XMc=K_N09i5R1nM;+1P7+GB3sHL8k z2-%_Wn|^BALxRncmrwBRDS@pasH?c6y@5bhcna-w#|0pp`+dv^=TADytD)m8x-AJQ z|16XL)6o1M6Q62w0o;RDP4y$KlY4fFfoS%+eU2dda-WT%A|xFPyVsS@K>#$n7S5dd z3%CCswCNCC*Ce#{j%1Vp)QBca3{1n*P2R{^FNyf4DsWI#zFExvT(>J{3Aa_ZxgX>cI_YK~BTex*c4$sW^{s?w2c@XL2=qEg~*y@5e1GGjAj49q1z&ox&>fcw4v31G?Y1Z z=KYkjMe?!>NwIkxk(Mr<&@*i*3}QrEo6%bEurl3Y)v>>$P(SD5g%q52K&}D;<8qDQ zma_SIhDlL7SkxIGg2#mTfyd0Ew1ebuIRu#fA(uzh4*N?6`$J)Im$-G?rqG^JN;PvTB8to_1)Ek z7NfN8c?5F*QSQj~Q})yPikk(PWgJ%bbaoE;?GrPMGaDWVR>g+W3rD*Uyc#_rKmhgL_>fq&|0 z9APV6aJnr?b=tcFw>`*+Rej%K(HS83t0~4`c>S=#M^JWE@)I5&@k1AXyaJ*u3}S<; z+d$uSG%9V6&O?nyo3Eb8I}C_4PODZG>tKaOgkA+uau- zduS3K^Dcx`OY$%(Cx=d)E>7S%8%FFmQ?&3mDr+6<@denj zs{SM)oi<5yytC(r-osBsea9*kLIcj?@Z-IylnD)DoHyOh_t|@IF$=m;mnttSBDCPP z$)e5Ka%z-_!|}D5NHw{ZMpcevfg)%R%JHPkKnyKr-H6%uD*YErHBwA$b*tnL3^x2b z!FEa9y+0?YN$N%qiF5H@bky-pRK~g}Q~IoJu~DuxQB2vimHlH78yh5GQ33`}fDK!? z$a5z4`pf^~@d_MU|Ew9o&(6o%)0tZvqt9-un87BO?THKxtl^fTw(}LmV)tt_AT{Sv z=Crfid@>F zMp>4%7l=onv<&<)tTQa%OQZ?*)740`ndDF~@di9!<7t0^__+H0Bc3JV598X85YzbT z3k6KmXw*On4=bpyRw*-w@=3DDYZ$8GgQ`uk7oL^gY3cvppyTiY1lp{XmhvY1QWIa= z=^XB;!eEE*#tY)J+#LK_Dzmy4E!m#nb5C?KlJTJCzoev08)d31v453{$WL0)ko#qv ze+ieJzyTNT9zJ0z^yZw|*h94qcuO*dNFgVwusA_b*ZC66~})9+=^ef7V4fd-Ftd%rGWmj}KGhH+f=FsQ(3jGt!eI zn9DZRZfi9triDKsq3hg?;zksRT9=g$_r5SkpSq4=zKzFF;|+1R3S$w*OY z8CL2j`c0xChDrSRN!l|C>t$X?$+YO9b)*bmR}lgTWn|5ml1N*jlMrM*rU3bk4m{%Hcm6+*8-|EV!DV_G zSCXCf$(23~^5Zeuj1or)@b8b`D3CiiR@6jdl79LrrqQ6ja{k-Gh1jFWOgPDwaY^P= z01XER$I%AKx58>Iq?k=k7vFOKc=E(p8}L~1T%dnUQbI0h;rrmucV)|=EIIE&hhncx zeJ5V#9;_h;;lLS=l(+S5Y1Q9aP*iih1aE8m7@T=_K(|p?`#wJHO%XC9lq)!Z4=s#7 z${5qPxcdqO6+zfaO9?(<70bw{e*G*)Oo3|UH<*QWQ@8Y&6ct=bN7IU7vA*$gDKQiO zT1^jm8YF2NyeA^7p(ULMT5wvt0E;IMdG00SSk0~+C3CD+A1XV@F;k@7xTN5JtyRm= zH)c$Q(kgJeVW6x&eP;L8?RE-WuV}fML*RHS`eT z4?)F)Lqq%7m#P}1iLW;!YYl$FYI@TNjy6Udt#Ni~)t@CKBpj#Z{&tI2vexe2sSz3Q zjUKTwNMBpqG3Y<)pU`IVGt!71K0!8}6u&UU-&*T_DESNHTQo4>QK zQNZ!<7pe6Zb@@`4j49eRT@&2I1?pw7zp_BenZXd)5Yui5O$hb3H~1t~YLq0brpMc+ zW@cuz^JWp*g`vtOP4gJIw0_P0<Jtpx*gO8q-O{vYHjg$kEVe#_FQ{H>G3j zGam1^h{y3}7=Ye`9LE;A$I20N=De@y)%=^JBf0`OuCazbD@V{&Q)gC#eDI;cM+6ks zxyF>AElD0=+>~7^X^@W7k34p+4H}t71pF|F=6l(56@}=d-gk`uL37z}ZB86?wz=wx zkT+OKDBm7XRMNJJDpvOH>Rl`mS>;j(2`v(3?(m15I>9u_B_#%HY#inp1-M=yjNr7z1k%s3H3Z*+SrYKvFi_foH+n;zD0Hso;=>peO*7*wsw zrZb7wXKA8O2u(zDC|D9x+$30v5tS6TaSLsFtFai@^3=PXOg>%-_`D)62HNcyFv~GQ zS_x88QszBw*&?!qRZvU2))hX;wH>l5x7*u(;@R5f9~!73l;L11OtXp=lvtL~+t1-P zb6kx@bL!K{xEg=C0)$W=x#VUo_BO<=(!$I^GnI`fgY(c^_GEI%Y(zejTkfYGY9>lQ z3B1Mv3{y(7y_c;77lrzrI4(XxUW|L;5=WBG#joI66hK^-qS-tnS+YESvcpHgVw=tX zjJjW!CWcl0EHay|=oPSBH}8EKnRU}u8W8ZPf}Gv=F11UxwL=Z+F@nW`7$Q{~ci65; zabTYJ300v_uC*WMyhW5Ut6yO*V=*R-{$fArqxWRDH6n#SA#`7(6rVZ$aE?;t3#j*r zl?WDuC>*r(>8?kCxlNLAI_Fpk)RRy_YB4MkjSq_T2p%QJq+3F)kaOTtKWPZ$Fe;#> zCG5~SD+?Jl$^8;eV@3sr4?C3yI5T~Mu8L=Z49>!UPPg54x>Kypm}h`kg}{BqCSga! zZ|qqikMlftibmxtCEaltPqAxQy>MtIt?*IX54nQ?s&x>0X3q175KdnCF9}8^Oq;vV zdqa(_uOuNvy}aJZJr%uy!(e#riI6;f zEUli9G%%3k=QxU(fK9b1Sk}$k=1Rs`u%2{+!&*r?hd^WdkxVgNNMv?)_8+;+BZVQO z7sllsr{dS*z)H^r_O{U!N^F%l#j_Sh-b|xs`=G*jq9m=pEiMnulj|Vzi6;oqb+(SN zf2p)}A~!$h>K}iU9uu^J_}#8%9joGFr;0MF9b_g0r9U{uDt+D8r+4lO{(|$?{K7dP zFhxoes~r#W>gu6$1dR7`XEjJ=nYB?%stPZDHZ!r!z1xDa%~LsM ztBl~e73akf73zcq<2S8`=L-Aa=L7Sdip~F!h3W0$n%`%KPB+JjqKa8WiX6MD)ZC-M zmHS8cy<5$x+X*(Ff5~QxaQ$}Nks50m5*DzK<{zoj(UOm)X0@4N*pesVJfv$wV*+_n_>D1j|)VW6Z8QA@+e*2bbkz4lgo9Iq2?^`AX zMr%z43DUL`9KND@q~1<;D4X`kxt;oOQb-|iPa4Xwiw!+Jw1t3mh~?nNT~fS&33zsB(pX!s}< z(+d3m86B9Qp+JKo{=bX@G$@$=w&0P~AYGN*j1-^;8i;`%fgR`#wvtH`4$u()1Q=#b a<_%HQX3s*X0StK$_$kV&$&^W(2LC@!_r6B} literal 0 HcmV?d00001 diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md new file mode 100644 index 00000000..e27a0f92 --- /dev/null +++ b/blog/posts/ios-vs-android.md @@ -0,0 +1,74 @@ +--- +date: + created: 2025-05-19T20:15:00Z +categories: + - Opinion +authors: + - fria +tags: + - Security + - iOS + - Android +preview: +--- + +# iOS vs Android Security: What Each Can Learn from the Other + +Both Android and iOS run on the vast majority of our mobile devices, meaning they are entrusted with our most sensitive data. While they trade blows, there are areas where the two differ in security features and philosophy. + +## Source Model + +One of the most glaring differences is the source model of each operating system: iOS is *mostly* closed source while Android is *mostly* open source, I'll get to what I mean by that in a bit. + +### iOS + +iOS is a closed-source operating system, but it's based on the open-source [XNU kernel](https://github.com/apple-oss-distributions/xnu). The kernel handles almost everything on the operating system, so it's good that such a vital component is openly available to examine and do what you want with. + +It's important to note that being open-source doesn't [inherently make software secure](https://seirdy.one/posts/2022/02/02/floss-security/), but it can be helpful for anyone wanting to audit the code. + +I'd like to see Apple realease its entire operating system as open source in order to foster a spirit of openness and allow for [reproducible builds](https://reproducible-builds.org), allowing third parties to verify that the downloaded binaries match the released source code. As of now, that's impossible thanks to iOS's closed nature. A fully open-source iOS would also be the first step in third-party + +### Android + +The beating heart of Android is the [Android Open Source Project](https://source.android.com) (AOSP). AOSP is essentially a complete open-source mobile operating system on its own. Android was designed from the beginning to be used by lots of different companies for their own mobile phone offerings, so the open nature is useful toward that goal. + +However, AOSP is only a barebones operating system. OEMs are expected to add their own proprietary components to make their own, custom user experience. This is why most Android phones you buy are full of proprietary software like Facebook and other OEM software; companies that sell Android phones mainly use AOSP as a secure base to then run on their phones with proprietary drivers and their own custom Android. While the openness of AOSP is great, the OEMs making the phones ultimately ruin it. + +Because AOSP is open source though, non-OEM third parties such as [GrapheneOS](https://grapheneos.org) have made their own fully open-source Android operating systems. GrapheneOS supports [reproducible builds](https://grapheneos.org/build#reproducible-builds). + +Many custom AOSP operating systems, while being open source, actually reduce security from AOSP through delayed updates and not supporting important Android security features like [Verified Boot](https://source.android.com/docs/security/features/verifiedboot) (this problem applies to many open source Android operating systems, but not GrapheneOS as they explicitly aim to never downgrade security from AOSP). + +A problem inherent to being downstream of AOSP, third-party operating systems also must wait for Google to [ship patches and updates](https://x.com/grapheneos/status/1964561043906048183) for them to apply. Ultimately they are up to the whims of the upstream project which is not ideal. + +## Hardware + +Hardware is vital to security. Modern smartphones are complicated, with lots of different processors and components, all runnng their own firmware and with their own potential security vulnerabilities. It's important to lock down these components as much as possible. + +### iOS + +Apple makes their own SoC on their platforms, which affords them a lot of control over how it works. You can read about how they integrate their hardware tightly on their [Apple Platform Security](https://support.apple.com/guide/security/hardware-security-overview-secf020d1074/web) page. + +Apple has started to replace other components as well, with their newest phones boasting their N1 wireless chip that handles WiFi, Bluetooth, and Thread connectivity as well as their in-house cellular modem. Apple has a lot of control over the components in their phones which avoids supply-chain issues that other OEMs run into, with each third-party component relying on a third party to [patch security vulnerabilities](https://www.binarly.io/blog/the-firmware-supply-chain-security-is-broken-can-we-fix-it) and fix bugs in their firmware. + +![Graphic showing the supply chain of various OEMs, and Apple bypassing the whole supply chain because they use their own firmware and hardware](../assets/images/ios-vs-android/binarly-graphic.png) + + + +Apple can deal with vulnerabilities themselves when they're reported instead of waiting for a third party to fix it. According to their [docs](https://support.apple.com/guide/security/peripheral-processor-security-seca500d4f2b/1/web/1): + +>Whenever possible, Apple works to reduce the number of peripheral processors necessary and to avoid designs that require firmware. But when separate processors with their own firmware are required, efforts are taken to help ensure an attacker can’t persist on that processor. + +They take care to reduce attack surface by disabling debug interfaces and signing the firmware with keys stored in Apple's own hardware security modules. + +Apple also supports all the important hardware security features you'd want, like a [Secure Element](https://support.apple.com/guide/security/secure-enclave-sec59b0b31ff/1/web/1) for secure cryptography and secret storage, secure [biometric hardware](https://support.apple.com/guide/security/biometric-security-sec067eb0c9e/1/web/1) including 3D face scans for Face ID, hardware-backed [indicator lights](https://theapplewiki.com/wiki/Secure_Indicator_Light) for camera and microphone, [hardware killswitches](https://support.apple.com/guide/security/hardware-microphone-disconnect-secbbd20b00b/1/web/1) for the microphone on iPads, and [MTE](https://security.apple.com/blog/memory-integrity-enforcement/) for their latest iPhones. + +Processors that deal with networking are isolated via an [IOMMU](https://support.apple.com/guide/security/security-features-connecting-wireless-sec8a67fa93d/1/web/1#sec7e0184776) so that they can't access each others' memory. + +Overall, Apple does an excellent job with hardware security, most Android OEMs could stand to learn from them. + +### Android + +Because Android is used by so many different OEMs, you often don't know what you're getting in terms of hardware security. Android devices, particularly cheaper phones, often lack security features such as a [secure element](https://developer.android.com/privacy-and-security/keystore) or [MTE support](https://developer.android.com/ndk/guides/arm-mte#hwsupport). + +There aren't really many examples in the Android world of an OEM with the same level of control over their hardware as Apple. Most Android OEMs are going to use third party SoC's and other components, which introduces possible supply chain issues with trusting third-party firmware and potential delays with security updates. + From 6d2c97711684c85f651d762d5b89c7ec10a99de8 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Fri, 26 Sep 2025 06:15:11 -0500 Subject: [PATCH 02/68] add app store --- blog/posts/ios-vs-android.md | 32 +++++++++++++++++++++++++++++++- 1 file changed, 31 insertions(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index e27a0f92..9b28a0fd 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -14,7 +14,7 @@ preview: # iOS vs Android Security: What Each Can Learn from the Other -Both Android and iOS run on the vast majority of our mobile devices, meaning they are entrusted with our most sensitive data. While they trade blows, there are areas where the two differ in security features and philosophy. +Both Android and iOS run on the vast majority of our mobile devices, meaning they are entrusted with our most sensitive data. While they trade blows, there are areas where the two differ in security features and philosophy. ## Source Model @@ -72,3 +72,33 @@ Because Android is used by so many different OEMs, you often don't know what you There aren't really many examples in the Android world of an OEM with the same level of control over their hardware as Apple. Most Android OEMs are going to use third party SoC's and other components, which introduces possible supply chain issues with trusting third-party firmware and potential delays with security updates. +## App Store + +Android and iOS have very different approaches in terms of downloading and acquiring apps. + +### iOS + +iOS restricts app downloads to their own App Store. Apple claims this is for security purposes, but it restricts user freedom and makes it possible for Apple to [censor](https://9to5mac.com/2024/09/28/apple-cooperating-with-russia-to-remove-vpn-apps-from-app-store/) apps in certain regions. + +The App Store does enforce certain [security](https://support.apple.com/guide/security/about-app-store-security-secb8f887a15/1/web/1) properties, mainly through the App Review process. This process can't catch everything though, and [malware](https://securelist.com/sparkcat-stealer-in-app-store-and-google-play/115385/) still slips through the cracks. + +The lack of third-party app store support means that it's not possible to use an app store with better security properties than the Apple App Store. For example, apps in the App Store have Apple's DRM, which makes reproducible builds [impossible](https://github.com/signalapp/Signal-iOS/issues/641#:~:text=So%20while%20truly%20reproducible%20builds%20are%20not%20possible). If one wanted to use an app store without this security regression, they'd be out of luck. + +One positive of the App Store though is they enforce things like a [minimum SDK](https://developer.apple.com/app-store/submitting/) requirement. Apps built targetting earlier SDK's can be missing newer security improvements and potentially have access to more data. + +In the EU, Apple was forced to allow [third-party app stores](https://developer.apple.com/support/dma-and-apps-in-the-eu/) and sideloading in iOS. In order to accomodate the extra security risk, they implemented the same [notarization](https://developer.apple.com/documentation/Security/notarizing-macos-software-before-distribution) feature from macOS. It would be nice to see them roll this out globally, but it seems to be locked to the EU for now. + +### Android + +Android takes the opposite approach and lets you simply download and run apps from the internet. This gives you much more freedom as a user but could potentially open you up to more malicious apps, for example apps that abuse [accessibility permissions](https://blog.pradeo.com/accessibility-services-mobile-analysis-malware) to gain deep access to your device. + +The Google Play Store sets a strict [SDK level requirement](https://developer.android.com/google/play/requirements/target-sdk), but apps downaloaded outside the Google Play Store have much more leniency. Sideloaded apps can target very old SDK levels, which means they won't have the same security restrictions as apps targetting newer SDK's. The biggest restriction that seems to exist in the OS preventing running older SDK's is if an app targets an SDK at or below Android 5.1 (!?) you'll get a warning message. For reference, Android 5 came out in 2014. + +I think Android could stand to enforce a higher SDK level and simply refuse to run apps that target lower than say a few versions ago. There's no reason to support apps that think they're on Android 5. + +GrapheneOS raises the minimum SDK from AOSP. + +Because of Android's support for third-party app stores, it's possible to use an app store with superior security to the Google Play Store. [Accrescent](https://accrescent.app) is just such an example. + +Accrescent allows for developers to control their own signing keys, and doesn't require an account, among other improvements. This is an improvement over the Google Play Store where Google controls the signing keys and you need a Google account to use it. + From f80d56129fafd9fbc14d093c05a4fc68a6381005 Mon Sep 17 00:00:00 2001 From: redoomed1 Date: Fri, 26 Sep 2025 07:08:41 -0700 Subject: [PATCH 03/68] style: Shorten links Signed-off-by: redoomed1 --- blog/posts/ios-vs-android.md | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 9b28a0fd..985e626d 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -24,7 +24,7 @@ One of the most glaring differences is the source model of each operating system iOS is a closed-source operating system, but it's based on the open-source [XNU kernel](https://github.com/apple-oss-distributions/xnu). The kernel handles almost everything on the operating system, so it's good that such a vital component is openly available to examine and do what you want with. -It's important to note that being open-source doesn't [inherently make software secure](https://seirdy.one/posts/2022/02/02/floss-security/), but it can be helpful for anyone wanting to audit the code. +It's important to note that being open-source doesn't [inherently make software secure](https://seirdy.one/posts/2022/02/02/floss-security), but it can be helpful for anyone wanting to audit the code. I'd like to see Apple realease its entire operating system as open source in order to foster a spirit of openness and allow for [reproducible builds](https://reproducible-builds.org), allowing third parties to verify that the downloaded binaries match the released source code. As of now, that's impossible thanks to iOS's closed nature. A fully open-source iOS would also be the first step in third-party @@ -48,11 +48,11 @@ Hardware is vital to security. Modern smartphones are complicated, with lots of Apple makes their own SoC on their platforms, which affords them a lot of control over how it works. You can read about how they integrate their hardware tightly on their [Apple Platform Security](https://support.apple.com/guide/security/hardware-security-overview-secf020d1074/web) page. -Apple has started to replace other components as well, with their newest phones boasting their N1 wireless chip that handles WiFi, Bluetooth, and Thread connectivity as well as their in-house cellular modem. Apple has a lot of control over the components in their phones which avoids supply-chain issues that other OEMs run into, with each third-party component relying on a third party to [patch security vulnerabilities](https://www.binarly.io/blog/the-firmware-supply-chain-security-is-broken-can-we-fix-it) and fix bugs in their firmware. +Apple has started to replace other components as well, with their newest phones boasting their N1 wireless chip that handles WiFi, Bluetooth, and Thread connectivity as well as their in-house cellular modem. Apple has a lot of control over the components in their phones which avoids supply-chain issues that other OEMs run into, with each third-party component relying on a third party to [patch security vulnerabilities](https://binarly.io/blog/the-firmware-supply-chain-security-is-broken-can-we-fix-it) and fix bugs in their firmware. ![Graphic showing the supply chain of various OEMs, and Apple bypassing the whole supply chain because they use their own firmware and hardware](../assets/images/ios-vs-android/binarly-graphic.png) - + Apple can deal with vulnerabilities themselves when they're reported instead of waiting for a third party to fix it. According to their [docs](https://support.apple.com/guide/security/peripheral-processor-security-seca500d4f2b/1/web/1): @@ -60,7 +60,7 @@ Apple can deal with vulnerabilities themselves when they're reported instead of They take care to reduce attack surface by disabling debug interfaces and signing the firmware with keys stored in Apple's own hardware security modules. -Apple also supports all the important hardware security features you'd want, like a [Secure Element](https://support.apple.com/guide/security/secure-enclave-sec59b0b31ff/1/web/1) for secure cryptography and secret storage, secure [biometric hardware](https://support.apple.com/guide/security/biometric-security-sec067eb0c9e/1/web/1) including 3D face scans for Face ID, hardware-backed [indicator lights](https://theapplewiki.com/wiki/Secure_Indicator_Light) for camera and microphone, [hardware killswitches](https://support.apple.com/guide/security/hardware-microphone-disconnect-secbbd20b00b/1/web/1) for the microphone on iPads, and [MTE](https://security.apple.com/blog/memory-integrity-enforcement/) for their latest iPhones. +Apple also supports all the important hardware security features you'd want, like a [Secure Element](https://support.apple.com/guide/security/secure-enclave-sec59b0b31ff/1/web/1) for secure cryptography and secret storage, secure [biometric hardware](https://support.apple.com/guide/security/biometric-security-sec067eb0c9e/1/web/1) including 3D face scans for Face ID, hardware-backed [indicator lights](https://theapplewiki.com/wiki/Secure_Indicator_Light) for camera and microphone, [hardware killswitches](https://support.apple.com/guide/security/hardware-microphone-disconnect-secbbd20b00b/1/web/1) for the microphone on iPads, and [MTE](https://security.apple.com/blog/memory-integrity-enforcement) for their latest iPhones. Processors that deal with networking are isolated via an [IOMMU](https://support.apple.com/guide/security/security-features-connecting-wireless-sec8a67fa93d/1/web/1#sec7e0184776) so that they can't access each others' memory. @@ -78,15 +78,15 @@ Android and iOS have very different approaches in terms of downloading and acqui ### iOS -iOS restricts app downloads to their own App Store. Apple claims this is for security purposes, but it restricts user freedom and makes it possible for Apple to [censor](https://9to5mac.com/2024/09/28/apple-cooperating-with-russia-to-remove-vpn-apps-from-app-store/) apps in certain regions. +iOS restricts app downloads to their own App Store. Apple claims this is for security purposes, but it restricts user freedom and makes it possible for Apple to [censor](https://9to5mac.com/2024/09/28/apple-cooperating-with-russia-to-remove-vpn-apps-from-app-store) apps in certain regions. -The App Store does enforce certain [security](https://support.apple.com/guide/security/about-app-store-security-secb8f887a15/1/web/1) properties, mainly through the App Review process. This process can't catch everything though, and [malware](https://securelist.com/sparkcat-stealer-in-app-store-and-google-play/115385/) still slips through the cracks. +The App Store does enforce certain [security](https://support.apple.com/guide/security/about-app-store-security-secb8f887a15/1/web/1) properties, mainly through the App Review process. This process can't catch everything though, and [malware](https://securelist.com/sparkcat-stealer-in-app-store-and-google-play/115385) still slips through the cracks. The lack of third-party app store support means that it's not possible to use an app store with better security properties than the Apple App Store. For example, apps in the App Store have Apple's DRM, which makes reproducible builds [impossible](https://github.com/signalapp/Signal-iOS/issues/641#:~:text=So%20while%20truly%20reproducible%20builds%20are%20not%20possible). If one wanted to use an app store without this security regression, they'd be out of luck. -One positive of the App Store though is they enforce things like a [minimum SDK](https://developer.apple.com/app-store/submitting/) requirement. Apps built targetting earlier SDK's can be missing newer security improvements and potentially have access to more data. +One positive of the App Store though is they enforce things like a [minimum SDK](https://developer.apple.com/app-store/submitting) requirement. Apps built targetting earlier SDK's can be missing newer security improvements and potentially have access to more data. -In the EU, Apple was forced to allow [third-party app stores](https://developer.apple.com/support/dma-and-apps-in-the-eu/) and sideloading in iOS. In order to accomodate the extra security risk, they implemented the same [notarization](https://developer.apple.com/documentation/Security/notarizing-macos-software-before-distribution) feature from macOS. It would be nice to see them roll this out globally, but it seems to be locked to the EU for now. +In the EU, Apple was forced to allow [third-party app stores](https://developer.apple.com/support/dma-and-apps-in-the-eu) and sideloading in iOS. In order to accomodate the extra security risk, they implemented the same [notarization](https://developer.apple.com/documentation/Security/notarizing-macos-software-before-distribution) feature from macOS. It would be nice to see them roll this out globally, but it seems to be locked to the EU for now. ### Android From 10d2844161b960bae41593b00b0353848afbe0c9 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Fri, 26 Sep 2025 12:22:27 -0500 Subject: [PATCH 04/68] add alternate OS support --- blog/posts/ios-vs-android.md | 27 +++++++++++++++++++++++++++ 1 file changed, 27 insertions(+) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 985e626d..23f84b72 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -102,3 +102,30 @@ Because of Android's support for third-party app stores, it's possible to use an Accrescent allows for developers to control their own signing keys, and doesn't require an account, among other improvements. This is an improvement over the Google Play Store where Google controls the signing keys and you need a Google account to use it. +## Alternate OS Support + +Support for installing alternate operating systems isn't just important for user freedom, it's needed so that third parties can make thier own, more secure and more private operating systems than what comes pre-installed. + +### iOS + +In order to install any apps or use many features on iOS, you need an [Apple Account](https://account.apple.com). Apple Accounts ask for your real name and require a phone number to use, on top of tying your app and other purchases to an account. While iOS is known to be privacy-friendly, Apple's [privacy policy](https://www.apple.com/legal/privacy/en-ww/) leaves a lot to be desired. + +iOS doesn't allow you to unlock the bootloader to install another operating system. While [jailbreaking](https://en.wikipedia.org/wiki/IOS_jailbreaking) is possible, it requires exploiting your device and ultimately your security will be much worse. + +iOS should allow for fully unlocking and relocking the bootloader for alternate operating systems, so a version of iOS without any user data being sent to Apple can be installed. + +This goes along with open sourcing their OS as well. When Apple eventually drops support for devices, it would be good to still be able to get updates through a third-party OS, although they wouldn't be able to update the firmware. + +Alternate OS's can also allow people to more fully utilize the hardware security features. For example, the [MTE](https://security.apple.com/blog/memory-integrity-enforcement/) support in newer iPhones currently doesn't cover everything in the OS, just "the kernel and over 70 userland processes" as well as being optional for app developers to enable. An alternate OS could be more strict and enable it for everything in the OS as well as apps by default, with a toggle to disable it if they crash. + +### Android + +While on paper Android is much more free in this regard, many OEMs don't properly support fully unlocking and relocking the bootloader. Google Pixels are really your only option on Android in this regard. + +The open nature of Android is ruined a bit by most of the OEMs, like [Samsung](https://x.com/GrapheneOS/status/1960374409572610192#m). + +GrapheneOS is probably the best example of what an alternate OS can achieve. They've made [significant security improvements](https://grapheneos.org/features) over the default Pixel OS and AOSP. + +GrapheneOS utilizes hardware features like MTE, which is locked behind [Advanced Protection](https://support.google.com/accounts/answer/9764949?hl=en) normally, by default and with significantly [more coverage](https://x.com/GrapheneOS/status/1965810573066768865#m). + +They also disable USB at the [hardware level](https://grapheneos.org/features#usb-c-port-and-pogo-pins-control). This is a demonstrable security improvement, as forensics companies like [Cellebrite](https://discuss.grapheneos.org/d/14344-cellebrite-premium-july-2024-documentation) have leaked documentation showing they're not able to get into GrapheneOS devices above a 2022 patch level. \ No newline at end of file From b25b9f4e6726e7dc84c1ca83f3a4f82fd6209c0c Mon Sep 17 00:00:00 2001 From: Jonah Aragon Date: Fri, 26 Sep 2025 14:52:41 -0500 Subject: [PATCH 05/68] update timestamp --- blog/posts/ios-vs-android.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 23f84b72..dc97d78e 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -1,6 +1,6 @@ --- date: - created: 2025-05-19T20:15:00Z + created: 2025-09-27T17:00:00Z categories: - Opinion authors: @@ -12,7 +12,7 @@ tags: preview: --- -# iOS vs Android Security: What Each Can Learn from the Other +# iOS vs Android Security: What They Can Learn From Each Other Both Android and iOS run on the vast majority of our mobile devices, meaning they are entrusted with our most sensitive data. While they trade blows, there are areas where the two differ in security features and philosophy. @@ -26,7 +26,7 @@ iOS is a closed-source operating system, but it's based on the open-source [XNU It's important to note that being open-source doesn't [inherently make software secure](https://seirdy.one/posts/2022/02/02/floss-security), but it can be helpful for anyone wanting to audit the code. -I'd like to see Apple realease its entire operating system as open source in order to foster a spirit of openness and allow for [reproducible builds](https://reproducible-builds.org), allowing third parties to verify that the downloaded binaries match the released source code. As of now, that's impossible thanks to iOS's closed nature. A fully open-source iOS would also be the first step in third-party +I'd like to see Apple realease its entire operating system as open source in order to foster a spirit of openness and allow for [reproducible builds](https://reproducible-builds.org), allowing third parties to verify that the downloaded binaries match the released source code. As of now, that's impossible thanks to iOS's closed nature. A fully open-source iOS would also be the first step in third-party ### Android @@ -128,4 +128,4 @@ GrapheneOS is probably the best example of what an alternate OS can achieve. The GrapheneOS utilizes hardware features like MTE, which is locked behind [Advanced Protection](https://support.google.com/accounts/answer/9764949?hl=en) normally, by default and with significantly [more coverage](https://x.com/GrapheneOS/status/1965810573066768865#m). -They also disable USB at the [hardware level](https://grapheneos.org/features#usb-c-port-and-pogo-pins-control). This is a demonstrable security improvement, as forensics companies like [Cellebrite](https://discuss.grapheneos.org/d/14344-cellebrite-premium-july-2024-documentation) have leaked documentation showing they're not able to get into GrapheneOS devices above a 2022 patch level. \ No newline at end of file +They also disable USB at the [hardware level](https://grapheneos.org/features#usb-c-port-and-pogo-pins-control). This is a demonstrable security improvement, as forensics companies like [Cellebrite](https://discuss.grapheneos.org/d/14344-cellebrite-premium-july-2024-documentation) have leaked documentation showing they're not able to get into GrapheneOS devices above a 2022 patch level. From 3b6d03ba24fbc89589306350be9b96b2359ada70 Mon Sep 17 00:00:00 2001 From: Jonah Aragon Date: Fri, 26 Sep 2025 14:56:55 -0500 Subject: [PATCH 06/68] Spell/grammar pass --- blog/posts/ios-vs-android.md | 22 +++++++++++----------- 1 file changed, 11 insertions(+), 11 deletions(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index dc97d78e..1cba58f7 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -26,13 +26,13 @@ iOS is a closed-source operating system, but it's based on the open-source [XNU It's important to note that being open-source doesn't [inherently make software secure](https://seirdy.one/posts/2022/02/02/floss-security), but it can be helpful for anyone wanting to audit the code. -I'd like to see Apple realease its entire operating system as open source in order to foster a spirit of openness and allow for [reproducible builds](https://reproducible-builds.org), allowing third parties to verify that the downloaded binaries match the released source code. As of now, that's impossible thanks to iOS's closed nature. A fully open-source iOS would also be the first step in third-party +I'd like to see Apple release its entire operating system as open source in order to foster a spirit of openness and allow for [reproducible builds](https://reproducible-builds.org), allowing third parties to verify that the downloaded binaries match the released source code. As of now, that's impossible thanks to iOS's closed nature. A fully open-source iOS would also be the first step in third-party ### Android The beating heart of Android is the [Android Open Source Project](https://source.android.com) (AOSP). AOSP is essentially a complete open-source mobile operating system on its own. Android was designed from the beginning to be used by lots of different companies for their own mobile phone offerings, so the open nature is useful toward that goal. -However, AOSP is only a barebones operating system. OEMs are expected to add their own proprietary components to make their own, custom user experience. This is why most Android phones you buy are full of proprietary software like Facebook and other OEM software; companies that sell Android phones mainly use AOSP as a secure base to then run on their phones with proprietary drivers and their own custom Android. While the openness of AOSP is great, the OEMs making the phones ultimately ruin it. +However, AOSP is only a bare-bones operating system. OEMs are expected to add their own proprietary components to make their own, custom user experience. This is why most Android phones you buy are full of proprietary software like Facebook and other OEM software; companies that sell Android phones mainly use AOSP as a secure base to then run on their phones with proprietary drivers and their own custom Android. While the openness of AOSP is great, the OEMs making the phones ultimately ruin it. Because AOSP is open source though, non-OEM third parties such as [GrapheneOS](https://grapheneos.org) have made their own fully open-source Android operating systems. GrapheneOS supports [reproducible builds](https://grapheneos.org/build#reproducible-builds). @@ -42,13 +42,13 @@ A problem inherent to being downstream of AOSP, third-party operating systems al ## Hardware -Hardware is vital to security. Modern smartphones are complicated, with lots of different processors and components, all runnng their own firmware and with their own potential security vulnerabilities. It's important to lock down these components as much as possible. +Hardware is vital to security. Modern smartphones are complicated, with lots of different processors and components, all running their own firmware and with their own potential security vulnerabilities. It's important to lock down these components as much as possible. ### iOS Apple makes their own SoC on their platforms, which affords them a lot of control over how it works. You can read about how they integrate their hardware tightly on their [Apple Platform Security](https://support.apple.com/guide/security/hardware-security-overview-secf020d1074/web) page. -Apple has started to replace other components as well, with their newest phones boasting their N1 wireless chip that handles WiFi, Bluetooth, and Thread connectivity as well as their in-house cellular modem. Apple has a lot of control over the components in their phones which avoids supply-chain issues that other OEMs run into, with each third-party component relying on a third party to [patch security vulnerabilities](https://binarly.io/blog/the-firmware-supply-chain-security-is-broken-can-we-fix-it) and fix bugs in their firmware. +Apple has started to replace other components as well, with their newest phones boasting their N1 wireless chip that handles Wi-Fi, Bluetooth, and Thread connectivity as well as their in-house cellular modem. Apple has a lot of control over the components in their phones which avoids supply-chain issues that other OEMs run into, with each third-party component relying on a third party to [patch security vulnerabilities](https://binarly.io/blog/the-firmware-supply-chain-security-is-broken-can-we-fix-it) and fix bugs in their firmware. ![Graphic showing the supply chain of various OEMs, and Apple bypassing the whole supply chain because they use their own firmware and hardware](../assets/images/ios-vs-android/binarly-graphic.png) @@ -60,9 +60,9 @@ Apple can deal with vulnerabilities themselves when they're reported instead of They take care to reduce attack surface by disabling debug interfaces and signing the firmware with keys stored in Apple's own hardware security modules. -Apple also supports all the important hardware security features you'd want, like a [Secure Element](https://support.apple.com/guide/security/secure-enclave-sec59b0b31ff/1/web/1) for secure cryptography and secret storage, secure [biometric hardware](https://support.apple.com/guide/security/biometric-security-sec067eb0c9e/1/web/1) including 3D face scans for Face ID, hardware-backed [indicator lights](https://theapplewiki.com/wiki/Secure_Indicator_Light) for camera and microphone, [hardware killswitches](https://support.apple.com/guide/security/hardware-microphone-disconnect-secbbd20b00b/1/web/1) for the microphone on iPads, and [MTE](https://security.apple.com/blog/memory-integrity-enforcement) for their latest iPhones. +Apple also supports all the important hardware security features you'd want, like a [Secure Element](https://support.apple.com/guide/security/secure-enclave-sec59b0b31ff/1/web/1) for secure cryptography and secret storage, secure [biometric hardware](https://support.apple.com/guide/security/biometric-security-sec067eb0c9e/1/web/1) including 3D face scans for Face ID, hardware-backed [indicator lights](https://theapplewiki.com/wiki/Secure_Indicator_Light) for camera and microphone, [hardware kill switches](https://support.apple.com/guide/security/hardware-microphone-disconnect-secbbd20b00b/1/web/1) for the microphone on iPads, and [MTE](https://security.apple.com/blog/memory-integrity-enforcement) for their latest iPhones. -Processors that deal with networking are isolated via an [IOMMU](https://support.apple.com/guide/security/security-features-connecting-wireless-sec8a67fa93d/1/web/1#sec7e0184776) so that they can't access each others' memory. +Processors that deal with networking are isolated via an [IOMMU](https://support.apple.com/guide/security/security-features-connecting-wireless-sec8a67fa93d/1/web/1#sec7e0184776) so that they can't access each other's memory. Overall, Apple does an excellent job with hardware security, most Android OEMs could stand to learn from them. @@ -84,15 +84,15 @@ The App Store does enforce certain [security](https://support.apple.com/guide/se The lack of third-party app store support means that it's not possible to use an app store with better security properties than the Apple App Store. For example, apps in the App Store have Apple's DRM, which makes reproducible builds [impossible](https://github.com/signalapp/Signal-iOS/issues/641#:~:text=So%20while%20truly%20reproducible%20builds%20are%20not%20possible). If one wanted to use an app store without this security regression, they'd be out of luck. -One positive of the App Store though is they enforce things like a [minimum SDK](https://developer.apple.com/app-store/submitting) requirement. Apps built targetting earlier SDK's can be missing newer security improvements and potentially have access to more data. +One positive of the App Store though is they enforce things like a [minimum SDK](https://developer.apple.com/app-store/submitting) requirement. Apps built targeting earlier SDK's can be missing newer security improvements and potentially have access to more data. -In the EU, Apple was forced to allow [third-party app stores](https://developer.apple.com/support/dma-and-apps-in-the-eu) and sideloading in iOS. In order to accomodate the extra security risk, they implemented the same [notarization](https://developer.apple.com/documentation/Security/notarizing-macos-software-before-distribution) feature from macOS. It would be nice to see them roll this out globally, but it seems to be locked to the EU for now. +In the EU, Apple was forced to allow [third-party app stores](https://developer.apple.com/support/dma-and-apps-in-the-eu) and sideloading in iOS. In order to accommodate the extra security risk, they implemented the same [notarization](https://developer.apple.com/documentation/Security/notarizing-macos-software-before-distribution) feature from macOS. It would be nice to see them roll this out globally, but it seems to be locked to the EU for now. ### Android Android takes the opposite approach and lets you simply download and run apps from the internet. This gives you much more freedom as a user but could potentially open you up to more malicious apps, for example apps that abuse [accessibility permissions](https://blog.pradeo.com/accessibility-services-mobile-analysis-malware) to gain deep access to your device. -The Google Play Store sets a strict [SDK level requirement](https://developer.android.com/google/play/requirements/target-sdk), but apps downaloaded outside the Google Play Store have much more leniency. Sideloaded apps can target very old SDK levels, which means they won't have the same security restrictions as apps targetting newer SDK's. The biggest restriction that seems to exist in the OS preventing running older SDK's is if an app targets an SDK at or below Android 5.1 (!?) you'll get a warning message. For reference, Android 5 came out in 2014. +The Google Play Store sets a strict [SDK level requirement](https://developer.android.com/google/play/requirements/target-sdk), but apps downloaded outside the Google Play Store have much more leniency. Sideloaded apps can target very old SDK levels, which means they won't have the same security restrictions as apps targeting newer SDK's. The biggest restriction that seems to exist in the OS preventing running older SDK's is if an app targets an SDK at or below Android 5.1 (!?) you'll get a warning message. For reference, Android 5 came out in 2014. I think Android could stand to enforce a higher SDK level and simply refuse to run apps that target lower than say a few versions ago. There's no reason to support apps that think they're on Android 5. @@ -100,11 +100,11 @@ GrapheneOS raises the minimum SDK from AOSP. Because of Android's support for third-party app stores, it's possible to use an app store with superior security to the Google Play Store. [Accrescent](https://accrescent.app) is just such an example. -Accrescent allows for developers to control their own signing keys, and doesn't require an account, among other improvements. This is an improvement over the Google Play Store where Google controls the signing keys and you need a Google account to use it. +Accrescent allows for developers to control their own signing keys, and doesn't require an account, among other improvements. This is an improvement over the Google Play Store where Google controls the signing keys, and you need a Google account to use it. ## Alternate OS Support -Support for installing alternate operating systems isn't just important for user freedom, it's needed so that third parties can make thier own, more secure and more private operating systems than what comes pre-installed. +Support for installing alternate operating systems isn't just important for user freedom, it's needed so that third parties can make their own, more secure and more private operating systems than what comes pre-installed. ### iOS From 156e98d8e32e6d4c8067c7e6106473057c354290 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Fri, 26 Sep 2025 15:13:59 -0500 Subject: [PATCH 07/68] add permissions --- blog/posts/ios-vs-android.md | 34 ++++++++++++++++++++++++++++++++++ 1 file changed, 34 insertions(+) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 1cba58f7..9bb46f07 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -129,3 +129,37 @@ GrapheneOS is probably the best example of what an alternate OS can achieve. The GrapheneOS utilizes hardware features like MTE, which is locked behind [Advanced Protection](https://support.google.com/accounts/answer/9764949?hl=en) normally, by default and with significantly [more coverage](https://x.com/GrapheneOS/status/1965810573066768865#m). They also disable USB at the [hardware level](https://grapheneos.org/features#usb-c-port-and-pogo-pins-control). This is a demonstrable security improvement, as forensics companies like [Cellebrite](https://discuss.grapheneos.org/d/14344-cellebrite-premium-july-2024-documentation) have leaked documentation showing they're not able to get into GrapheneOS devices above a 2022 patch level. + +## Permissions + +Both operating systems sandbox their apps to prevent access to most of the system, but many things like the camera and microphone are left to users to decide if they allow them or not. iOS and Android differ in what permissions they offer and the granularity of the permissions. + +### iOS + +iOS has historically been ahead of AOSP in terms of the permissions it offers. + +iOS's [paste permission](https://developer.apple.com/documentation/uikit/uipasteboard/) prevents apps from nefariously reading data from your clipboard without your permission, something AOSP lacks still. + +iOS added the [Local Network](https://developer.apple.com/documentation/technotes/tn3179-understanding-local-network-privacy) permission in iOS 14, preventing apps from accessing other devices on your local network such as other phones or computers, maybe even network drives with sensitive data on them. Android later [added this permission](https://developer.android.com/privacy-and-security/local-network-permission) in Android 16, albeit currently as opt-in for developers. + +Their [contact picker](https://support.apple.com/guide/iphone/control-access-to-contacts-iph9536aa9a5/ios) from iOS 18 allows you to select specific individual contacts you want an app to have access to without giving the app access to your full contact list, a feature which AOSP has yet to implement (although GrapheneOS has a more [granular version](https://grapheneos.org/usage#contact-scopes) of this that they made first). + +iOS 26 recently added a [Wired Accessories](https://support.apple.com/en-us/111806) permission as well. + +While iOS tends to lead in terms of the sheer number of permissions, they could stand to be more granular. On iOS, once you grant a permission, it tends to stay until you remove it. They have a "one time" option for location, but seemingly not for anything else. + +iOS's permissions also tend to lean toward individual apps rather than global permissions. There's no global toggle for the camera or microphone for example like on Android. When you try to disable WiFi or Bluetooth globally through the Control Center on iOS, they won't actually fully disable: you need to go to the settings in order to properly disable them (unless you have Airplane Mode on for some reason). + +There's also the matter of some permissions only being available in certain regions, like apparently Chinese iPhones have a granular [network permission](https://sspai.com/post/35720) that can allow you grant specific apps network access. This would be a huge security improvement on iOS, and it's a feature that's already been implemented so it's quite confusing why they wouldn't ship this feature globally. + +These permissions might protect you from third-party apps, but Apple's own apps can actually [bypass the system permissions](https://blog.xpnsec.com/bypassing-macos-privacy-controls/#:~:text=A%20quick%20review%20of%20Calendar's,How%20can%20we%20subvert%20this?). Allowing their own apps privileged access in the system is, in my opinion, both a privacy and security issue. This means that any Apple app could access your camera, microphone, etc without you knowing about it. I'd like to see Apple not make their own apps privileged, I think that would make users more comfortable and give them more controll over their system. + +### Android + +Android's permissions tend to lag behind iOS, but they usually end up implementing them in the end. The strength on Android is the global toggles for things like camera and microphone, and much wider use of "one time" permissions. + +GrapheneOS greatly expands on the permissions AOSP offers, giving highly granular options such as [Contact Scopes](https://grapheneos.org/usage#contact-scopes) that allow you not only to pick what specific contacts you want, but also specific information from each contact. + +GrapheneOS also implements a user-facing Network permission allowing apps to individually be granted network access. + +You would think with examples of these features already being implemented on *their own platform*, AOSP would go ahead and add them, but that doesn't seem to be the case. I'd like to see Android implement equivalent versions of these permissions to what GrapheneOS offers, the research and development work has already been done on how they should work, they just need to copy it. From 871960eac35c98a7d6d09d6711f126511fa50fc0 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Fri, 26 Sep 2025 15:23:49 -0500 Subject: [PATCH 08/68] fix unfinished sentence --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 9bb46f07..3a2a9bf5 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -26,7 +26,7 @@ iOS is a closed-source operating system, but it's based on the open-source [XNU It's important to note that being open-source doesn't [inherently make software secure](https://seirdy.one/posts/2022/02/02/floss-security), but it can be helpful for anyone wanting to audit the code. -I'd like to see Apple release its entire operating system as open source in order to foster a spirit of openness and allow for [reproducible builds](https://reproducible-builds.org), allowing third parties to verify that the downloaded binaries match the released source code. As of now, that's impossible thanks to iOS's closed nature. A fully open-source iOS would also be the first step in third-party +I'd like to see Apple release its entire operating system as open source in order to foster a spirit of openness and allow for [reproducible builds](https://reproducible-builds.org), allowing third parties to verify that the downloaded binaries match the released source code. As of now, that's impossible thanks to iOS's closed nature. A fully open-source iOS would also be the first step in third-party operating system support on the platform. ### Android From 730ffd69da373018fb1217b56778c7c342289ed0 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Fri, 26 Sep 2025 21:26:35 -0500 Subject: [PATCH 09/68] add ios security scoped files info --- blog/posts/ios-vs-android.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 3a2a9bf5..eecd3242 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -140,6 +140,8 @@ iOS has historically been ahead of AOSP in terms of the permissions it offers. iOS's [paste permission](https://developer.apple.com/documentation/uikit/uipasteboard/) prevents apps from nefariously reading data from your clipboard without your permission, something AOSP lacks still. +Since iOS 13, apps need to go through the [system file picker](https://developer.apple.com/documentation/uikit/providing-access-to-directories) and are only granted access to the specific files the user allows via a security-scoped URL, they don't gain access to the full filesystem. + iOS added the [Local Network](https://developer.apple.com/documentation/technotes/tn3179-understanding-local-network-privacy) permission in iOS 14, preventing apps from accessing other devices on your local network such as other phones or computers, maybe even network drives with sensitive data on them. Android later [added this permission](https://developer.android.com/privacy-and-security/local-network-permission) in Android 16, albeit currently as opt-in for developers. Their [contact picker](https://support.apple.com/guide/iphone/control-access-to-contacts-iph9536aa9a5/ios) from iOS 18 allows you to select specific individual contacts you want an app to have access to without giving the app access to your full contact list, a feature which AOSP has yet to implement (although GrapheneOS has a more [granular version](https://grapheneos.org/usage#contact-scopes) of this that they made first). From 99279dd70b7031701876f0e1ac4bf157a2c94603 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Fri, 26 Sep 2025 21:38:16 -0500 Subject: [PATCH 10/68] update wired accessories for ios --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index eecd3242..673df753 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -146,7 +146,7 @@ iOS added the [Local Network](https://developer.apple.com/documentation/technote Their [contact picker](https://support.apple.com/guide/iphone/control-access-to-contacts-iph9536aa9a5/ios) from iOS 18 allows you to select specific individual contacts you want an app to have access to without giving the app access to your full contact list, a feature which AOSP has yet to implement (although GrapheneOS has a more [granular version](https://grapheneos.org/usage#contact-scopes) of this that they made first). -iOS 26 recently added a [Wired Accessories](https://support.apple.com/en-us/111806) permission as well. +iOS 26 recently added a [Wired Accessories](https://support.apple.com/en-us/111806) setting as well so you can change how the phone behaves when a wired accessory is connected. While iOS tends to lead in terms of the sheer number of permissions, they could stand to be more granular. On iOS, once you grant a permission, it tends to stay until you remove it. They have a "one time" option for location, but seemingly not for anything else. From 6a3125422002a3082d439ad48355af6f91d4c38a Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Fri, 26 Sep 2025 22:26:21 -0500 Subject: [PATCH 11/68] add apple security research device program --- blog/posts/ios-vs-android.md | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 673df753..1c45f4b2 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -118,6 +118,12 @@ This goes along with open sourcing their OS as well. When Apple eventually drops Alternate OS's can also allow people to more fully utilize the hardware security features. For example, the [MTE](https://security.apple.com/blog/memory-integrity-enforcement/) support in newer iPhones currently doesn't cover everything in the OS, just "the kernel and over 70 userland processes" as well as being optional for app developers to enable. An alternate OS could be more strict and enable it for everything in the OS as well as apps by default, with a toggle to disable it if they crash. +Apple's refusal to allow rooting iPhones also stifles security researchers' ability to do their work, many of them having to resort to exploiting the phone just to have the access they need. + +Apple's [Security Research Device](https://security.apple.com/research-device/) program is an acknowledgement of this problem. It offers built-in access to make security research much easier. However, it's only offered as a "12-month renewable loan" (meaning you never own the device) and is only available to people with "a proven track record of success in finding security issues on Apple platforms, or other modern operating systems and platforms". This means if you're not already an established security researcher, you won't have access to it. + +In my opinion, this strict locking down of the platform stifles up-and-coming security researchers. Apple should allow users to root their devices if they want, with a warning about the security implications. + ### Android While on paper Android is much more free in this regard, many OEMs don't properly support fully unlocking and relocking the bootloader. Google Pixels are really your only option on Android in this regard. From 12192f16956e5e042b9f2c553b12bd3a3c668c90 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Fri, 26 Sep 2025 22:31:24 -0500 Subject: [PATCH 12/68] change "root" to unlock bootloader --- blog/posts/ios-vs-android.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 1c45f4b2..7e16d1a0 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -118,11 +118,11 @@ This goes along with open sourcing their OS as well. When Apple eventually drops Alternate OS's can also allow people to more fully utilize the hardware security features. For example, the [MTE](https://security.apple.com/blog/memory-integrity-enforcement/) support in newer iPhones currently doesn't cover everything in the OS, just "the kernel and over 70 userland processes" as well as being optional for app developers to enable. An alternate OS could be more strict and enable it for everything in the OS as well as apps by default, with a toggle to disable it if they crash. -Apple's refusal to allow rooting iPhones also stifles security researchers' ability to do their work, many of them having to resort to exploiting the phone just to have the access they need. +Apple's refusal to allow unlocking the bootloader on iPhones also stifles security researchers' ability to do their work, many of them having to resort to exploiting the phone just to have the access they need. Apple's [Security Research Device](https://security.apple.com/research-device/) program is an acknowledgement of this problem. It offers built-in access to make security research much easier. However, it's only offered as a "12-month renewable loan" (meaning you never own the device) and is only available to people with "a proven track record of success in finding security issues on Apple platforms, or other modern operating systems and platforms". This means if you're not already an established security researcher, you won't have access to it. -In my opinion, this strict locking down of the platform stifles up-and-coming security researchers. Apple should allow users to root their devices if they want, with a warning about the security implications. +In my opinion, this strict locking down of the platform stifles up-and-coming security researchers. Apple should allow users to unlock the bootloader on their devices if they want, with a warning about the security implications. ### Android From 5530f6522705a325012cbfd24a97e0c21f22f7af Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Fri, 26 Sep 2025 22:31:59 -0500 Subject: [PATCH 13/68] add link for unlocking bootloader --- blog/posts/ios-vs-android.md | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 7e16d1a0..e672012d 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -126,7 +126,7 @@ In my opinion, this strict locking down of the platform stifles up-and-coming se ### Android -While on paper Android is much more free in this regard, many OEMs don't properly support fully unlocking and relocking the bootloader. Google Pixels are really your only option on Android in this regard. +While on paper Android is much more free in this regard, many OEMs don't properly support fully [unlocking and relocking](https://source.android.com/docs/core/architecture/bootloader/locking_unlocking) the bootloader. Google Pixels are really your only option on Android in this regard. The open nature of Android is ruined a bit by most of the OEMs, like [Samsung](https://x.com/GrapheneOS/status/1960374409572610192#m). @@ -136,6 +136,8 @@ GrapheneOS utilizes hardware features like MTE, which is locked behind [Advanced They also disable USB at the [hardware level](https://grapheneos.org/features#usb-c-port-and-pogo-pins-control). This is a demonstrable security improvement, as forensics companies like [Cellebrite](https://discuss.grapheneos.org/d/14344-cellebrite-premium-july-2024-documentation) have leaked documentation showing they're not able to get into GrapheneOS devices above a 2022 patch level. + + ## Permissions Both operating systems sandbox their apps to prevent access to most of the system, but many things like the camera and microphone are left to users to decide if they allow them or not. iOS and Android differ in what permissions they offer and the granularity of the permissions. From 109478a0aa6ab88d57d64ad57df11c4c7814cc1c Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Fri, 26 Sep 2025 22:36:29 -0500 Subject: [PATCH 14/68] add security research to android section --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index e672012d..8cf28722 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -136,7 +136,7 @@ GrapheneOS utilizes hardware features like MTE, which is locked behind [Advanced They also disable USB at the [hardware level](https://grapheneos.org/features#usb-c-port-and-pogo-pins-control). This is a demonstrable security improvement, as forensics companies like [Cellebrite](https://discuss.grapheneos.org/d/14344-cellebrite-premium-july-2024-documentation) have leaked documentation showing they're not able to get into GrapheneOS devices above a 2022 patch level. - +The ability to unlock the bootloader on Android devices is a huge boon for security research as well. ## Permissions From 18fe537b0cb2fe172cdea27cee36494401e96dc3 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Fri, 26 Sep 2025 23:42:34 -0500 Subject: [PATCH 15/68] add google play services --- blog/posts/ios-vs-android.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 8cf28722..95625481 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -173,3 +173,5 @@ GrapheneOS greatly expands on the permissions AOSP offers, giving highly granula GrapheneOS also implements a user-facing Network permission allowing apps to individually be granted network access. You would think with examples of these features already being implemented on *their own platform*, AOSP would go ahead and add them, but that doesn't seem to be the case. I'd like to see Android implement equivalent versions of these permissions to what GrapheneOS offers, the research and development work has already been done on how they should work, they just need to copy it. + +The stock OS you get on your phone suffers from a similar problem as iOS in that Google Play Services are [highly privileged](https://developers.google.com/android/guides/permissions#:~:text=Google%20Play%20services%20automatically%20obtains%20all%20permissions%20it%20needs%20to%20support%20its%20APIs.) in the system. GrapheneOS's [Sandboxed Google Play Services](https://grapheneos.org/features#sandboxed-google-play) provides to option to install it inside the standard app sandbox, preventing it from having any access outside what a normal app would have. This is a massive boost in security and privacy and is how Google Play Services should operate by default. From ebc7c4eeac2e70e5406c0ca192fd24d10ffdcadc Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Sat, 27 Sep 2025 00:33:27 -0500 Subject: [PATCH 16/68] add link to android full filesystem access --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 95625481..d97cff16 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -148,7 +148,7 @@ iOS has historically been ahead of AOSP in terms of the permissions it offers. iOS's [paste permission](https://developer.apple.com/documentation/uikit/uipasteboard/) prevents apps from nefariously reading data from your clipboard without your permission, something AOSP lacks still. -Since iOS 13, apps need to go through the [system file picker](https://developer.apple.com/documentation/uikit/providing-access-to-directories) and are only granted access to the specific files the user allows via a security-scoped URL, they don't gain access to the full filesystem. +Since iOS 13, apps need to go through the [system file picker](https://developer.apple.com/documentation/uikit/providing-access-to-directories) and are only granted access to the specific files the user allows via a security-scoped URL, they don't gain access to the full filesystem like apps can on [Android](https://developer.android.com/training/data-storage/manage-all-files#:~:text=Android%20provides%20a%20special%20app%20access%20called%20all%2Dfiles%20access%20for%20these%20situations.). iOS added the [Local Network](https://developer.apple.com/documentation/technotes/tn3179-understanding-local-network-privacy) permission in iOS 14, preventing apps from accessing other devices on your local network such as other phones or computers, maybe even network drives with sensitive data on them. Android later [added this permission](https://developer.android.com/privacy-and-security/local-network-permission) in Android 16, albeit currently as opt-in for developers. From ca3305e0c8e36371f88edcd312f462129264b823 Mon Sep 17 00:00:00 2001 From: redoomed1 Date: Sat, 27 Sep 2025 20:25:25 -0700 Subject: [PATCH 17/68] Apply minor suggestions from code review Signed-off-by: redoomed1 --- blog/posts/ios-vs-android.md | 26 +++++++++++++------------- 1 file changed, 13 insertions(+), 13 deletions(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index d97cff16..dacea3a0 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -24,13 +24,13 @@ One of the most glaring differences is the source model of each operating system iOS is a closed-source operating system, but it's based on the open-source [XNU kernel](https://github.com/apple-oss-distributions/xnu). The kernel handles almost everything on the operating system, so it's good that such a vital component is openly available to examine and do what you want with. -It's important to note that being open-source doesn't [inherently make software secure](https://seirdy.one/posts/2022/02/02/floss-security), but it can be helpful for anyone wanting to audit the code. +It's important to note that being open source [doesn't inherently make software secure](https://seirdy.one/posts/2022/02/02/floss-security), but it can be helpful for anyone wanting to audit the code. I'd like to see Apple release its entire operating system as open source in order to foster a spirit of openness and allow for [reproducible builds](https://reproducible-builds.org), allowing third parties to verify that the downloaded binaries match the released source code. As of now, that's impossible thanks to iOS's closed nature. A fully open-source iOS would also be the first step in third-party operating system support on the platform. ### Android -The beating heart of Android is the [Android Open Source Project](https://source.android.com) (AOSP). AOSP is essentially a complete open-source mobile operating system on its own. Android was designed from the beginning to be used by lots of different companies for their own mobile phone offerings, so the open nature is useful toward that goal. +The beating heart of Android is the [Android Open Source Project](https://source.android.com) (AOSP). AOSP is essentially a complete, open-source mobile OS on its own. Android was designed from the beginning to be used by lots of different companies for each of their own mobile phone offerings, so the open nature is useful toward that goal. However, AOSP is only a bare-bones operating system. OEMs are expected to add their own proprietary components to make their own, custom user experience. This is why most Android phones you buy are full of proprietary software like Facebook and other OEM software; companies that sell Android phones mainly use AOSP as a secure base to then run on their phones with proprietary drivers and their own custom Android. While the openness of AOSP is great, the OEMs making the phones ultimately ruin it. @@ -56,7 +56,7 @@ Apple has started to replace other components as well, with their newest phones Apple can deal with vulnerabilities themselves when they're reported instead of waiting for a third party to fix it. According to their [docs](https://support.apple.com/guide/security/peripheral-processor-security-seca500d4f2b/1/web/1): ->Whenever possible, Apple works to reduce the number of peripheral processors necessary and to avoid designs that require firmware. But when separate processors with their own firmware are required, efforts are taken to help ensure an attacker can’t persist on that processor. +> Whenever possible, Apple works to reduce the number of peripheral processors necessary and to avoid designs that require firmware. But when separate processors with their own firmware are required, efforts are taken to help ensure an attacker can’t persist on that processor. They take care to reduce attack surface by disabling debug interfaces and signing the firmware with keys stored in Apple's own hardware security modules. @@ -64,7 +64,7 @@ Apple also supports all the important hardware security features you'd want, lik Processors that deal with networking are isolated via an [IOMMU](https://support.apple.com/guide/security/security-features-connecting-wireless-sec8a67fa93d/1/web/1#sec7e0184776) so that they can't access each other's memory. -Overall, Apple does an excellent job with hardware security, most Android OEMs could stand to learn from them. +Overall, Apple does an excellent job with hardware security. Most Android OEMs could stand to learn from them. ### Android @@ -90,7 +90,7 @@ In the EU, Apple was forced to allow [third-party app stores](https://developer. ### Android -Android takes the opposite approach and lets you simply download and run apps from the internet. This gives you much more freedom as a user but could potentially open you up to more malicious apps, for example apps that abuse [accessibility permissions](https://blog.pradeo.com/accessibility-services-mobile-analysis-malware) to gain deep access to your device. +Android takes the opposite approach and lets you simply download and run apps from the internet. This gives you much more freedom as a user but could potentially open you up to more malicious apps, for example, apps that abuse [accessibility permissions](https://blog.pradeo.com/accessibility-services-mobile-analysis-malware) to gain deep access to your device. The Google Play Store sets a strict [SDK level requirement](https://developer.android.com/google/play/requirements/target-sdk), but apps downloaded outside the Google Play Store have much more leniency. Sideloaded apps can target very old SDK levels, which means they won't have the same security restrictions as apps targeting newer SDK's. The biggest restriction that seems to exist in the OS preventing running older SDK's is if an app targets an SDK at or below Android 5.1 (!?) you'll get a warning message. For reference, Android 5 came out in 2014. @@ -98,7 +98,7 @@ I think Android could stand to enforce a higher SDK level and simply refuse to r GrapheneOS raises the minimum SDK from AOSP. -Because of Android's support for third-party app stores, it's possible to use an app store with superior security to the Google Play Store. [Accrescent](https://accrescent.app) is just such an example. +Because of Android's support for third-party app stores, it's possible to use an app store with superior security to the Google Play Store. [Accrescent](https://accrescent.app) is one such an example. Accrescent allows for developers to control their own signing keys, and doesn't require an account, among other improvements. This is an improvement over the Google Play Store where Google controls the signing keys, and you need a Google account to use it. @@ -112,21 +112,21 @@ In order to install any apps or use many features on iOS, you need an [Apple Acc iOS doesn't allow you to unlock the bootloader to install another operating system. While [jailbreaking](https://en.wikipedia.org/wiki/IOS_jailbreaking) is possible, it requires exploiting your device and ultimately your security will be much worse. -iOS should allow for fully unlocking and relocking the bootloader for alternate operating systems, so a version of iOS without any user data being sent to Apple can be installed. +iOS should allow for fully unlocking and relocking the bootloader for alternate operating systems so that a version of iOS without any user data being sent to Apple can be installed. This goes along with open sourcing their OS as well. When Apple eventually drops support for devices, it would be good to still be able to get updates through a third-party OS, although they wouldn't be able to update the firmware. -Alternate OS's can also allow people to more fully utilize the hardware security features. For example, the [MTE](https://security.apple.com/blog/memory-integrity-enforcement/) support in newer iPhones currently doesn't cover everything in the OS, just "the kernel and over 70 userland processes" as well as being optional for app developers to enable. An alternate OS could be more strict and enable it for everything in the OS as well as apps by default, with a toggle to disable it if they crash. +Alternate operating systems can also allow people to more fully utilize the hardware security features. For example, the [MTE](https://security.apple.com/blog/memory-integrity-enforcement) support in newer iPhones currently doesn't cover everything in the OS, just "the kernel and over 70 userland processes," as well as being optional for app developers to enable. An alternate OS could be more strict and enable it for everything in the OS as well as apps by default, with a toggle to disable it if they crash. -Apple's refusal to allow unlocking the bootloader on iPhones also stifles security researchers' ability to do their work, many of them having to resort to exploiting the phone just to have the access they need. +Apple's refusal to allow unlocking the bootloader on iPhones also stifles security researchers' ability to do their work, with many of them having to resort to exploiting the phone just to have the access they need. -Apple's [Security Research Device](https://security.apple.com/research-device/) program is an acknowledgement of this problem. It offers built-in access to make security research much easier. However, it's only offered as a "12-month renewable loan" (meaning you never own the device) and is only available to people with "a proven track record of success in finding security issues on Apple platforms, or other modern operating systems and platforms". This means if you're not already an established security researcher, you won't have access to it. +Apple's [Security Research Device](https://security.apple.com/research-device) program is an acknowledgement of this problem. It offers built-in access to make security research much easier. However, it's only offered as a "12-month renewable loan" (meaning you never own the device) and is only available to people with "a proven track record of success in finding security issues on Apple platforms, or other modern operating systems and platforms". This means if you're not already an established security researcher, you won't have access to it. In my opinion, this strict locking down of the platform stifles up-and-coming security researchers. Apple should allow users to unlock the bootloader on their devices if they want, with a warning about the security implications. ### Android -While on paper Android is much more free in this regard, many OEMs don't properly support fully [unlocking and relocking](https://source.android.com/docs/core/architecture/bootloader/locking_unlocking) the bootloader. Google Pixels are really your only option on Android in this regard. +While Android is, on paper, much more free in terms of alternate OS support, many OEMs don't properly support fully [unlocking and relocking](https://source.android.com/docs/core/architecture/bootloader/locking_unlocking) the bootloader. Google Pixels are really your only option on Android in this regard. The open nature of Android is ruined a bit by most of the OEMs, like [Samsung](https://x.com/GrapheneOS/status/1960374409572610192#m). @@ -146,7 +146,7 @@ Both operating systems sandbox their apps to prevent access to most of the syste iOS has historically been ahead of AOSP in terms of the permissions it offers. -iOS's [paste permission](https://developer.apple.com/documentation/uikit/uipasteboard/) prevents apps from nefariously reading data from your clipboard without your permission, something AOSP lacks still. +iOS's [paste permission](https://developer.apple.com/documentation/uikit/uipasteboard) prevents apps from nefariously reading data from your clipboard without your permission, something AOSP lacks still. Since iOS 13, apps need to go through the [system file picker](https://developer.apple.com/documentation/uikit/providing-access-to-directories) and are only granted access to the specific files the user allows via a security-scoped URL, they don't gain access to the full filesystem like apps can on [Android](https://developer.android.com/training/data-storage/manage-all-files#:~:text=Android%20provides%20a%20special%20app%20access%20called%20all%2Dfiles%20access%20for%20these%20situations.). @@ -160,7 +160,7 @@ While iOS tends to lead in terms of the sheer number of permissions, they could iOS's permissions also tend to lean toward individual apps rather than global permissions. There's no global toggle for the camera or microphone for example like on Android. When you try to disable WiFi or Bluetooth globally through the Control Center on iOS, they won't actually fully disable: you need to go to the settings in order to properly disable them (unless you have Airplane Mode on for some reason). -There's also the matter of some permissions only being available in certain regions, like apparently Chinese iPhones have a granular [network permission](https://sspai.com/post/35720) that can allow you grant specific apps network access. This would be a huge security improvement on iOS, and it's a feature that's already been implemented so it's quite confusing why they wouldn't ship this feature globally. +There's also the matter of some permissions only being available in certain regions: Apparently, Chinese iPhones have a granular [network permission](https://sspai.com/post/35720) that can allow you grant specific apps network access. This would be a huge security improvement on iOS, and it's a feature that's already been implemented so it's quite confusing why they wouldn't ship this feature globally. These permissions might protect you from third-party apps, but Apple's own apps can actually [bypass the system permissions](https://blog.xpnsec.com/bypassing-macos-privacy-controls/#:~:text=A%20quick%20review%20of%20Calendar's,How%20can%20we%20subvert%20this?). Allowing their own apps privileged access in the system is, in my opinion, both a privacy and security issue. This means that any Apple app could access your camera, microphone, etc without you knowing about it. I'd like to see Apple not make their own apps privileged, I think that would make users more comfortable and give them more controll over their system. From d27f27120ae9c250632ad0c7668eb20192fd0469 Mon Sep 17 00:00:00 2001 From: redoomed1 Date: Sun, 28 Sep 2025 07:17:50 -0700 Subject: [PATCH 18/68] style: Undo slight wording change Signed-off-by: redoomed1 --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index dacea3a0..5f27066e 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -98,7 +98,7 @@ I think Android could stand to enforce a higher SDK level and simply refuse to r GrapheneOS raises the minimum SDK from AOSP. -Because of Android's support for third-party app stores, it's possible to use an app store with superior security to the Google Play Store. [Accrescent](https://accrescent.app) is one such an example. +Because of Android's support for third-party app stores, it's possible to use an app store with superior security to the Google Play Store. [Accrescent](https://accrescent.app) is just such an example. Accrescent allows for developers to control their own signing keys, and doesn't require an account, among other improvements. This is an improvement over the Google Play Store where Google controls the signing keys, and you need a Google account to use it. From 890795bbd42980acb183a1012721d106fdcfc877 Mon Sep 17 00:00:00 2001 From: redoomed1 Date: Sun, 28 Sep 2025 07:19:54 -0700 Subject: [PATCH 19/68] style: Fix typo Signed-off-by: redoomed1 --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 5f27066e..5771056b 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -162,7 +162,7 @@ iOS's permissions also tend to lean toward individual apps rather than global pe There's also the matter of some permissions only being available in certain regions: Apparently, Chinese iPhones have a granular [network permission](https://sspai.com/post/35720) that can allow you grant specific apps network access. This would be a huge security improvement on iOS, and it's a feature that's already been implemented so it's quite confusing why they wouldn't ship this feature globally. -These permissions might protect you from third-party apps, but Apple's own apps can actually [bypass the system permissions](https://blog.xpnsec.com/bypassing-macos-privacy-controls/#:~:text=A%20quick%20review%20of%20Calendar's,How%20can%20we%20subvert%20this?). Allowing their own apps privileged access in the system is, in my opinion, both a privacy and security issue. This means that any Apple app could access your camera, microphone, etc without you knowing about it. I'd like to see Apple not make their own apps privileged, I think that would make users more comfortable and give them more controll over their system. +These permissions might protect you from third-party apps, but Apple's own apps can actually [bypass the system permissions](https://blog.xpnsec.com/bypassing-macos-privacy-controls/#:~:text=A%20quick%20review%20of%20Calendar's,How%20can%20we%20subvert%20this?). Allowing their own apps privileged access in the system is, in my opinion, both a privacy and security issue. This means that any Apple app could access your camera, microphone, etc without you knowing about it. I'd like to see Apple not make their own apps privileged, I think that would make users more comfortable and give them more control over their system. ### Android From 0e3553a90d274186cb1f8cacf9ff1495c42eed18 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Sun, 28 Sep 2025 09:21:48 -0500 Subject: [PATCH 20/68] wording/capitalization Co-authored-by: redoomed1 Signed-off-by: fria <138676274+friadev@users.noreply.github.com> --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 5771056b..eb9f7cd2 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -174,4 +174,4 @@ GrapheneOS also implements a user-facing Network permission allowing apps to ind You would think with examples of these features already being implemented on *their own platform*, AOSP would go ahead and add them, but that doesn't seem to be the case. I'd like to see Android implement equivalent versions of these permissions to what GrapheneOS offers, the research and development work has already been done on how they should work, they just need to copy it. -The stock OS you get on your phone suffers from a similar problem as iOS in that Google Play Services are [highly privileged](https://developers.google.com/android/guides/permissions#:~:text=Google%20Play%20services%20automatically%20obtains%20all%20permissions%20it%20needs%20to%20support%20its%20APIs.) in the system. GrapheneOS's [Sandboxed Google Play Services](https://grapheneos.org/features#sandboxed-google-play) provides to option to install it inside the standard app sandbox, preventing it from having any access outside what a normal app would have. This is a massive boost in security and privacy and is how Google Play Services should operate by default. +The stock OS pre-installed on an Android phone suffers from a similar problem as iOS on an iPhone in that Google Play Services are [highly privileged](https://developers.google.com/android/guides/permissions#:~:text=Google%20Play%20services%20automatically%20obtains%20all%20permissions%20it%20needs%20to%20support%20its%20APIs.) in the OS. GrapheneOS's [sandboxed Google Play Services](https://grapheneos.org/features#sandboxed-google-play) provides to option to install it inside the standard app sandbox, preventing it from having any access outside what a normal app would have. This is a massive boost in security and privacy and is how Google Play Services should operate by default. From 89c26509ee7d2e9b7612c21a82d6ca795af70ee9 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Sun, 28 Sep 2025 09:23:07 -0500 Subject: [PATCH 21/68] wording Co-authored-by: redoomed1 Signed-off-by: fria <138676274+friadev@users.noreply.github.com> --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index eb9f7cd2..c1da3d8b 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -170,7 +170,7 @@ Android's permissions tend to lag behind iOS, but they usually end up implementi GrapheneOS greatly expands on the permissions AOSP offers, giving highly granular options such as [Contact Scopes](https://grapheneos.org/usage#contact-scopes) that allow you not only to pick what specific contacts you want, but also specific information from each contact. -GrapheneOS also implements a user-facing Network permission allowing apps to individually be granted network access. +GrapheneOS also implements a user-facing Network permission which allows you to grant network access to individual apps. You would think with examples of these features already being implemented on *their own platform*, AOSP would go ahead and add them, but that doesn't seem to be the case. I'd like to see Android implement equivalent versions of these permissions to what GrapheneOS offers, the research and development work has already been done on how they should work, they just need to copy it. From 8a4bf229fc03a2f7b7dbb2059d3324634ccadb6b Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Sun, 28 Sep 2025 09:23:44 -0500 Subject: [PATCH 22/68] wording Co-authored-by: redoomed1 Signed-off-by: fria <138676274+friadev@users.noreply.github.com> --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index c1da3d8b..f0e8528c 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -22,7 +22,7 @@ One of the most glaring differences is the source model of each operating system ### iOS -iOS is a closed-source operating system, but it's based on the open-source [XNU kernel](https://github.com/apple-oss-distributions/xnu). The kernel handles almost everything on the operating system, so it's good that such a vital component is openly available to examine and do what you want with. +iOS is a closed-source OS, but it's based on the open-source [XNU kernel](https://github.com/apple-oss-distributions/xnu). The kernel handles almost everything on the OS, so it's good that such a vital component is openly available to examine and test. It's important to note that being open source [doesn't inherently make software secure](https://seirdy.one/posts/2022/02/02/floss-security), but it can be helpful for anyone wanting to audit the code. From 7815c9ef0269eeadf4ef41ea655f88d89e05af2c Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Sun, 28 Sep 2025 15:13:44 -0500 Subject: [PATCH 23/68] add profile info --- blog/posts/ios-vs-android.md | 22 +++++++++++++++++++++- 1 file changed, 21 insertions(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index f0e8528c..c0e1d2b5 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -170,8 +170,28 @@ Android's permissions tend to lag behind iOS, but they usually end up implementi GrapheneOS greatly expands on the permissions AOSP offers, giving highly granular options such as [Contact Scopes](https://grapheneos.org/usage#contact-scopes) that allow you not only to pick what specific contacts you want, but also specific information from each contact. -GrapheneOS also implements a user-facing Network permission which allows you to grant network access to individual apps. +GrapheneOS also implements a user-facing [Network permission](https://grapheneos.org/features#network-permission-toggle) allowing apps to individually be granted network access. You would think with examples of these features already being implemented on *their own platform*, AOSP would go ahead and add them, but that doesn't seem to be the case. I'd like to see Android implement equivalent versions of these permissions to what GrapheneOS offers, the research and development work has already been done on how they should work, they just need to copy it. The stock OS pre-installed on an Android phone suffers from a similar problem as iOS on an iPhone in that Google Play Services are [highly privileged](https://developers.google.com/android/guides/permissions#:~:text=Google%20Play%20services%20automatically%20obtains%20all%20permissions%20it%20needs%20to%20support%20its%20APIs.) in the OS. GrapheneOS's [sandboxed Google Play Services](https://grapheneos.org/features#sandboxed-google-play) provides to option to install it inside the standard app sandbox, preventing it from having any access outside what a normal app would have. This is a massive boost in security and privacy and is how Google Play Services should operate by default. + +## Profiles + +Support for separate user profiles allows for strong separation of activities, similar to how different browser profiles allow you to separate your browsing. + +### iOS + +iOS doesn't allow for separate profiles. This is a major detriment on iOS as Android does support separate profiles, each encrypted with a separate encryption key.. + +iOS could benefit massively from introducing multiple user profiles. Apple has already implemented the feature on [iPadOS](https://support.apple.com/guide/deployment/shared-ipad-overview-dep9a34c2ba2/web) but requires the iPad to be supervised. + +### Android + +Android's support for separate [user profiles](https://source.android.com/docs/devices/admin/multi-user) take great pains to enforce separation of data using separate encryption keys and settings. + +It's intending for separate physical people, but it can easily be used to keep one person to keep data separate. Even Android themselves acknowledge this with [work profiles](https://www.android.com/enterprise/work-profile/) allowing businesses to keep their employees' personal data separate from their work data, preventing leakage either direction. + +Profiles also form the basis of Android's [Private Space](https://source.android.com/docs/security/features/private-space) feature, which allows you to make a secure silo for sensitive apps and data. + +The closest iOS gets is the ability to [lock and hide apps](https://support.apple.com/guide/iphone/lock-or-hide-or-an-app-iph00f208d05/ios), which is useful but not as strong as Android's profiles separation. \ No newline at end of file From 64e7d6c526cffda24145e262d254ae7d951c8b5e Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Tue, 30 Sep 2025 00:30:44 -0500 Subject: [PATCH 24/68] add insider attack resistance --- blog/posts/ios-vs-android.md | 16 +++++++++++++++- 1 file changed, 15 insertions(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index c0e1d2b5..c0d1b560 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -194,4 +194,18 @@ It's intending for separate physical people, but it can easily be used to keep o Profiles also form the basis of Android's [Private Space](https://source.android.com/docs/security/features/private-space) feature, which allows you to make a secure silo for sensitive apps and data. -The closest iOS gets is the ability to [lock and hide apps](https://support.apple.com/guide/iphone/lock-or-hide-or-an-app-iph00f208d05/ios), which is useful but not as strong as Android's profiles separation. \ No newline at end of file +The closest iOS gets is the ability to [lock and hide apps](https://support.apple.com/guide/iphone/lock-or-hide-or-an-app-iph00f208d05/ios), which is useful but not as strong as Android's profiles separation. + +## Insider Attack Resistance + +Both Android and iOS are highly secure against attacks on firmware and internal components thanks to their use of signatures to verify that the firmware is made by the OEM. But what if the attacker has access to the signing keys? + +### iOS + +Apple makes no mention of a feature protecting against insider attacks that I could find, which seems like a big omission. I think it's clear that you're expected to trust Apple fully on iOS, which is fair but I think it limits what security features they're willing to implement sometimes. + +### Android + +Android on the other hand implements [insider attack resistance](https://android-developers.googleblog.com/2018/05/insider-attack-resistance.html) by preventing the firmware on the secure element from being upgraded unless the correct user password is input. + +Specifically, this prevents a targeted malicious update against a specific user from working without the user's cooperation. This is a great security feature and very needed in a world where governments have tried to coerce companies into pushing a [targeted malicious update](https://www.apple.com/customer-letter/) before. \ No newline at end of file From d90c3c7a1696ecc4a1b369ad873a20e94bca29d7 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Tue, 30 Sep 2025 00:56:22 -0500 Subject: [PATCH 25/68] add browser --- blog/posts/ios-vs-android.md | 18 +++++++++++++++++- 1 file changed, 17 insertions(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index c0d1b560..fbb5228d 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -208,4 +208,20 @@ Apple makes no mention of a feature protecting against insider attacks that I co Android on the other hand implements [insider attack resistance](https://android-developers.googleblog.com/2018/05/insider-attack-resistance.html) by preventing the firmware on the secure element from being upgraded unless the correct user password is input. -Specifically, this prevents a targeted malicious update against a specific user from working without the user's cooperation. This is a great security feature and very needed in a world where governments have tried to coerce companies into pushing a [targeted malicious update](https://www.apple.com/customer-letter/) before. \ No newline at end of file +Specifically, this prevents a targeted malicious update against a specific user from working without the user's cooperation. This is a great security feature and very needed in a world where governments have tried to coerce companies into pushing a [targeted malicious update](https://www.apple.com/customer-letter/) before. + +## Browser + +The browser is a major way users are exposed to malware. Your browser runs untrusted code from multiple sources constantly, and any vulnerability could yield a treasure trove of data including bank account session tokens and passwords. + +### iOS + +On iOS, you're [locked to using WebKit](https://developer.apple.com/app-store/review/guidelines/#:~:text=Apps%20that%20browse%20the%20web%20must%20use%20the%20appropriate%20WebKit%20framework%20and%20WebKit%20JavaScript.). Any other browesr you install is essentially just a reskin of Safari. + +Apple did allow [alternate browser engines](https://developer.apple.com/support/alternative-browser-engines/) in the EU, but in other regions you're still locked to using WebKit. + +While Safari does offer good [privacy features](https://webkit.org/blog/15697/private-browsing-2-0/), it's lacking some important security protections that other browsers have like [site isolation](https://docs.webkit.org/Deep%20Dive/SiteIsolation.html#finding-what-needs-to-be-done), which they are currently working on implementing but it will be some time before it's done. + +Locking users out of other browsers stifles competition and user freedom, not to mention potentially [putting users at risk](https://predictors.fail/#:~:text=As%20pointed%20out%20by%20iLeakage%2C%20Safari%20lacks%20Site%20Isolation%2C%20a%20measure%20used%20to%20enforce%20that%20two%20different%20webpages%20not%20from%20the%20same%20domain%20can%20never%20be%20handled%20by%20the%20same%20process.) by locking them out of using browsers with faster updates and more advanced [security features](https://www.chromium.org/Home/chromium-security/site-isolation/). + +Apple should open up their ecosystem to allow for alternate browser engines globally instead of just in the EU. \ No newline at end of file From 4885fbae5e4ad2d8034651846e199c60a3d32198 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Tue, 30 Sep 2025 02:30:40 -0500 Subject: [PATCH 26/68] wording Co-authored-by: redoomed1 Signed-off-by: fria <138676274+friadev@users.noreply.github.com> --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index fbb5228d..2572c39e 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -172,7 +172,7 @@ GrapheneOS greatly expands on the permissions AOSP offers, giving highly granula GrapheneOS also implements a user-facing [Network permission](https://grapheneos.org/features#network-permission-toggle) allowing apps to individually be granted network access. -You would think with examples of these features already being implemented on *their own platform*, AOSP would go ahead and add them, but that doesn't seem to be the case. I'd like to see Android implement equivalent versions of these permissions to what GrapheneOS offers, the research and development work has already been done on how they should work, they just need to copy it. +You would think with examples of these features already being implemented on *their own platform*, AOSP would go ahead and add them, but that doesn't seem to be the case. I'd like to see Android implement equivalent versions of these permissions to what GrapheneOS offers. GrapheneOS has already developed and tested the permissions; Google just needs to copy them. The stock OS pre-installed on an Android phone suffers from a similar problem as iOS on an iPhone in that Google Play Services are [highly privileged](https://developers.google.com/android/guides/permissions#:~:text=Google%20Play%20services%20automatically%20obtains%20all%20permissions%20it%20needs%20to%20support%20its%20APIs.) in the OS. GrapheneOS's [sandboxed Google Play Services](https://grapheneos.org/features#sandboxed-google-play) provides to option to install it inside the standard app sandbox, preventing it from having any access outside what a normal app would have. This is a massive boost in security and privacy and is how Google Play Services should operate by default. From b0e0aa9289433a8aa1e927a8ec5c2257647ea856 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Tue, 30 Sep 2025 02:31:46 -0500 Subject: [PATCH 27/68] wording Co-authored-by: redoomed1 Signed-off-by: fria <138676274+friadev@users.noreply.github.com> --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 2572c39e..550d4d90 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -34,7 +34,7 @@ The beating heart of Android is the [Android Open Source Project](https://source However, AOSP is only a bare-bones operating system. OEMs are expected to add their own proprietary components to make their own, custom user experience. This is why most Android phones you buy are full of proprietary software like Facebook and other OEM software; companies that sell Android phones mainly use AOSP as a secure base to then run on their phones with proprietary drivers and their own custom Android. While the openness of AOSP is great, the OEMs making the phones ultimately ruin it. -Because AOSP is open source though, non-OEM third parties such as [GrapheneOS](https://grapheneos.org) have made their own fully open-source Android operating systems. GrapheneOS supports [reproducible builds](https://grapheneos.org/build#reproducible-builds). +Because AOSP is open source though, non-OEM third parties such as [GrapheneOS](https://grapheneos.org) have made their own fully open-source Android OS. Unlike stock Android operating systems, GrapheneOS supports [reproducible builds](https://grapheneos.org/build#reproducible-builds). Many custom AOSP operating systems, while being open source, actually reduce security from AOSP through delayed updates and not supporting important Android security features like [Verified Boot](https://source.android.com/docs/security/features/verifiedboot) (this problem applies to many open source Android operating systems, but not GrapheneOS as they explicitly aim to never downgrade security from AOSP). From 5b87b211bbbefbf5a7bdf7cc69a290901810530e Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Tue, 30 Sep 2025 02:32:39 -0500 Subject: [PATCH 28/68] wording Co-authored-by: redoomed1 Signed-off-by: fria <138676274+friadev@users.noreply.github.com> --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 550d4d90..0e4fd7af 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -38,7 +38,7 @@ Because AOSP is open source though, non-OEM third parties such as [GrapheneOS](h Many custom AOSP operating systems, while being open source, actually reduce security from AOSP through delayed updates and not supporting important Android security features like [Verified Boot](https://source.android.com/docs/security/features/verifiedboot) (this problem applies to many open source Android operating systems, but not GrapheneOS as they explicitly aim to never downgrade security from AOSP). -A problem inherent to being downstream of AOSP, third-party operating systems also must wait for Google to [ship patches and updates](https://x.com/grapheneos/status/1964561043906048183) for them to apply. Ultimately they are up to the whims of the upstream project which is not ideal. +One problem custom Android operating systems face is the inherent issue of being [downstream](https://en.wikipedia.org/wiki/Downstream_(software_development)) of AOSP, which means third-party operating systems must wait for the upstream project to ship patches and updates. In this case, AOSP-based operating systems are [at the whim of Google](https://x.com/grapheneos/status/1964561043906048183) for timely security patches and updates, which is not ideal. ## Hardware From 74866f9b6f1e25ea5740b61c95d21ca842f8d501 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Tue, 30 Sep 2025 02:33:05 -0500 Subject: [PATCH 29/68] wording Co-authored-by: redoomed1 Signed-off-by: fria <138676274+friadev@users.noreply.github.com> --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 0e4fd7af..f932afaf 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -26,7 +26,7 @@ iOS is a closed-source OS, but it's based on the open-source [XNU kernel](https: It's important to note that being open source [doesn't inherently make software secure](https://seirdy.one/posts/2022/02/02/floss-security), but it can be helpful for anyone wanting to audit the code. -I'd like to see Apple release its entire operating system as open source in order to foster a spirit of openness and allow for [reproducible builds](https://reproducible-builds.org), allowing third parties to verify that the downloaded binaries match the released source code. As of now, that's impossible thanks to iOS's closed nature. A fully open-source iOS would also be the first step in third-party operating system support on the platform. +I'd like to see Apple release the source code of its entire OS in order to foster a spirit of openness and enable [reproducible builds](https://reproducible-builds.org). The latter would allow third parties to verify that the downloaded binaries match the released source code. Currently, that's impossible due to iOS's closed nature. Furthermore, a fully open-source iOS would also be the first step in third-party OS support on the platform. ### Android From 3d687ffdf132e4bf96826f88d4f7d2eb6d909b9e Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Tue, 30 Sep 2025 02:34:36 -0500 Subject: [PATCH 30/68] wording Co-authored-by: redoomed1 Signed-off-by: fria <138676274+friadev@users.noreply.github.com> --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index f932afaf..a0d1d170 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -18,7 +18,7 @@ Both Android and iOS run on the vast majority of our mobile devices, meaning the ## Source Model -One of the most glaring differences is the source model of each operating system: iOS is *mostly* closed source while Android is *mostly* open source, I'll get to what I mean by that in a bit. +One of the most glaring differences is the source model of each operating system: iOS is *mostly* closed source while Android is *mostly* open source. Continue reading to learn the implications of this difference. ### iOS From 4bdcdc15ea82a2c0c6c61d34534ca575e21d653a Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Tue, 30 Sep 2025 02:35:08 -0500 Subject: [PATCH 31/68] wording Co-authored-by: redoomed1 Signed-off-by: fria <138676274+friadev@users.noreply.github.com> --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index a0d1d170..5b554d7b 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -32,7 +32,7 @@ I'd like to see Apple release the source code of its entire OS in order to foste The beating heart of Android is the [Android Open Source Project](https://source.android.com) (AOSP). AOSP is essentially a complete, open-source mobile OS on its own. Android was designed from the beginning to be used by lots of different companies for each of their own mobile phone offerings, so the open nature is useful toward that goal. -However, AOSP is only a bare-bones operating system. OEMs are expected to add their own proprietary components to make their own, custom user experience. This is why most Android phones you buy are full of proprietary software like Facebook and other OEM software; companies that sell Android phones mainly use AOSP as a secure base to then run on their phones with proprietary drivers and their own custom Android. While the openness of AOSP is great, the OEMs making the phones ultimately ruin it. +However, AOSP is only a bare-bones OS. OEMs are expected to add their own proprietary components to make a custom user experience specific to their brand. This is why most Android phones you buy are pre-installed with proprietary software like Facebook and other OEM software. Companies that sell Android phones mainly use AOSP as a secure base to then run on their phones with proprietary drivers and a custom Android OS. While the openness of AOSP is great, the OEMs producing the phones ultimately ruin it. Because AOSP is open source though, non-OEM third parties such as [GrapheneOS](https://grapheneos.org) have made their own fully open-source Android OS. Unlike stock Android operating systems, GrapheneOS supports [reproducible builds](https://grapheneos.org/build#reproducible-builds). From ba36368fcb57898fe0a50f00fc6140dad4aca425 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Tue, 30 Sep 2025 02:35:47 -0500 Subject: [PATCH 32/68] wording Co-authored-by: redoomed1 Signed-off-by: fria <138676274+friadev@users.noreply.github.com> --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 5b554d7b..5b1aa7e6 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -36,7 +36,7 @@ However, AOSP is only a bare-bones OS. OEMs are expected to add their own propri Because AOSP is open source though, non-OEM third parties such as [GrapheneOS](https://grapheneos.org) have made their own fully open-source Android OS. Unlike stock Android operating systems, GrapheneOS supports [reproducible builds](https://grapheneos.org/build#reproducible-builds). -Many custom AOSP operating systems, while being open source, actually reduce security from AOSP through delayed updates and not supporting important Android security features like [Verified Boot](https://source.android.com/docs/security/features/verifiedboot) (this problem applies to many open source Android operating systems, but not GrapheneOS as they explicitly aim to never downgrade security from AOSP). +Many open-source, custom AOSP-based operating systems actually reduce security from AOSP through delayed updates and lack of support for important Android security features like [Verified Boot](https://www.privacyguides.org/en/os/android-overview/#verified-boot). GrapheneOS is an exception as they explicitly aim to [never downgrade security from AOSP](https://grapheneos.org/features#:~:text=It%20starts%20from%20the%20strong%20baseline%20of%20the%20Android%20Open%20Source%20Project%20(AOSP)%20and%20takes%20great%20care%20to%20avoid%20increasing%20attack%20surface%20or%20hurting%20the%20strong%20security%20model.). One problem custom Android operating systems face is the inherent issue of being [downstream](https://en.wikipedia.org/wiki/Downstream_(software_development)) of AOSP, which means third-party operating systems must wait for the upstream project to ship patches and updates. In this case, AOSP-based operating systems are [at the whim of Google](https://x.com/grapheneos/status/1964561043906048183) for timely security patches and updates, which is not ideal. From 5ffbd8d85cf81933dc156b8bdf44015797716b4a Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Tue, 30 Sep 2025 02:37:31 -0500 Subject: [PATCH 33/68] link to android documentation for verified boot --- blog/posts/ios-vs-android.md | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 5b1aa7e6..4db969f2 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -36,7 +36,7 @@ However, AOSP is only a bare-bones OS. OEMs are expected to add their own propri Because AOSP is open source though, non-OEM third parties such as [GrapheneOS](https://grapheneos.org) have made their own fully open-source Android OS. Unlike stock Android operating systems, GrapheneOS supports [reproducible builds](https://grapheneos.org/build#reproducible-builds). -Many open-source, custom AOSP-based operating systems actually reduce security from AOSP through delayed updates and lack of support for important Android security features like [Verified Boot](https://www.privacyguides.org/en/os/android-overview/#verified-boot). GrapheneOS is an exception as they explicitly aim to [never downgrade security from AOSP](https://grapheneos.org/features#:~:text=It%20starts%20from%20the%20strong%20baseline%20of%20the%20Android%20Open%20Source%20Project%20(AOSP)%20and%20takes%20great%20care%20to%20avoid%20increasing%20attack%20surface%20or%20hurting%20the%20strong%20security%20model.). +Many open-source, custom AOSP-based operating systems actually reduce security from AOSP through delayed updates and lack of support for important Android security features like [Verified Boot](https://source.android.com/docs/security/features/verifiedboot). GrapheneOS is an exception as they explicitly aim to [never downgrade security from AOSP](https://grapheneos.org/features#:~:text=It%20starts%20from%20the%20strong%20baseline%20of%20the%20Android%20Open%20Source%20Project%20(AOSP)%20and%20takes%20great%20care%20to%20avoid%20increasing%20attack%20surface%20or%20hurting%20the%20strong%20security%20model.). One problem custom Android operating systems face is the inherent issue of being [downstream](https://en.wikipedia.org/wiki/Downstream_(software_development)) of AOSP, which means third-party operating systems must wait for the upstream project to ship patches and updates. In this case, AOSP-based operating systems are [at the whim of Google](https://x.com/grapheneos/status/1964561043906048183) for timely security patches and updates, which is not ideal. @@ -224,4 +224,7 @@ While Safari does offer good [privacy features](https://webkit.org/blog/15697/pr Locking users out of other browsers stifles competition and user freedom, not to mention potentially [putting users at risk](https://predictors.fail/#:~:text=As%20pointed%20out%20by%20iLeakage%2C%20Safari%20lacks%20Site%20Isolation%2C%20a%20measure%20used%20to%20enforce%20that%20two%20different%20webpages%20not%20from%20the%20same%20domain%20can%20never%20be%20handled%20by%20the%20same%20process.) by locking them out of using browsers with faster updates and more advanced [security features](https://www.chromium.org/Home/chromium-security/site-isolation/). -Apple should open up their ecosystem to allow for alternate browser engines globally instead of just in the EU. \ No newline at end of file +Apple should open up their ecosystem to allow for alternate browser engines globally instead of just in the EU. + +## Optional App Hardening + From 3242e37f811544987d570487926ca33a475e3de7 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Tue, 30 Sep 2025 02:38:27 -0500 Subject: [PATCH 34/68] wording Co-authored-by: redoomed1 Signed-off-by: fria <138676274+friadev@users.noreply.github.com> --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 4db969f2..16d55541 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -42,7 +42,7 @@ One problem custom Android operating systems face is the inherent issue of being ## Hardware -Hardware is vital to security. Modern smartphones are complicated, with lots of different processors and components, all running their own firmware and with their own potential security vulnerabilities. It's important to lock down these components as much as possible. +Hardware is vital to security. Modern smartphones pose a challenge with lots of processors and components, each with their own firmware and potential security vulnerabilities. It's important to lock down these components as much as possible. ### iOS From 20ecbd31a1b32b0de3fccf535252565c2c385561 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Tue, 30 Sep 2025 02:39:07 -0500 Subject: [PATCH 35/68] wording Co-authored-by: redoomed1 Signed-off-by: fria <138676274+friadev@users.noreply.github.com> --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 16d55541..b77b16f3 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -48,7 +48,7 @@ Hardware is vital to security. Modern smartphones pose a challenge with lots of Apple makes their own SoC on their platforms, which affords them a lot of control over how it works. You can read about how they integrate their hardware tightly on their [Apple Platform Security](https://support.apple.com/guide/security/hardware-security-overview-secf020d1074/web) page. -Apple has started to replace other components as well, with their newest phones boasting their N1 wireless chip that handles Wi-Fi, Bluetooth, and Thread connectivity as well as their in-house cellular modem. Apple has a lot of control over the components in their phones which avoids supply-chain issues that other OEMs run into, with each third-party component relying on a third party to [patch security vulnerabilities](https://binarly.io/blog/the-firmware-supply-chain-security-is-broken-can-we-fix-it) and fix bugs in their firmware. +Apple has started to replace other components as well, with their newest phones boasting their N1 wireless chip that handles Wi-Fi, Bluetooth, and Thread connectivity, as well as their in-house cellular modem. Apple has a lot of control over the components in their phones, which avoids supply chain issues that other OEMs encounter, where each component relies on a third party to [patch security vulnerabilities](https://binarly.io/blog/the-firmware-supply-chain-security-is-broken-can-we-fix-it) and fix bugs in their firmware. ![Graphic showing the supply chain of various OEMs, and Apple bypassing the whole supply chain because they use their own firmware and hardware](../assets/images/ios-vs-android/binarly-graphic.png) From b729f43ab30cf08916589137d4a0225bb38e303b Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Tue, 30 Sep 2025 02:39:27 -0500 Subject: [PATCH 36/68] wording Co-authored-by: redoomed1 Signed-off-by: fria <138676274+friadev@users.noreply.github.com> --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index b77b16f3..6cb5f4cc 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -54,7 +54,7 @@ Apple has started to replace other components as well, with their newest phones -Apple can deal with vulnerabilities themselves when they're reported instead of waiting for a third party to fix it. According to their [docs](https://support.apple.com/guide/security/peripheral-processor-security-seca500d4f2b/1/web/1): +Apple can patch vulnerabilities themselves when they're reported instead of waiting for a third party to fix them. According to their [docs](https://support.apple.com/guide/security/peripheral-processor-security-seca500d4f2b/1/web/1): > Whenever possible, Apple works to reduce the number of peripheral processors necessary and to avoid designs that require firmware. But when separate processors with their own firmware are required, efforts are taken to help ensure an attacker can’t persist on that processor. From cedcb1cb6e60bb14a54ce2766a05f9d029ce8872 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Tue, 30 Sep 2025 02:40:32 -0500 Subject: [PATCH 37/68] wording Co-authored-by: redoomed1 Signed-off-by: fria <138676274+friadev@users.noreply.github.com> --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 6cb5f4cc..437c7995 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -62,7 +62,7 @@ They take care to reduce attack surface by disabling debug interfaces and signin Apple also supports all the important hardware security features you'd want, like a [Secure Element](https://support.apple.com/guide/security/secure-enclave-sec59b0b31ff/1/web/1) for secure cryptography and secret storage, secure [biometric hardware](https://support.apple.com/guide/security/biometric-security-sec067eb0c9e/1/web/1) including 3D face scans for Face ID, hardware-backed [indicator lights](https://theapplewiki.com/wiki/Secure_Indicator_Light) for camera and microphone, [hardware kill switches](https://support.apple.com/guide/security/hardware-microphone-disconnect-secbbd20b00b/1/web/1) for the microphone on iPads, and [MTE](https://security.apple.com/blog/memory-integrity-enforcement) for their latest iPhones. -Processors that deal with networking are isolated via an [IOMMU](https://support.apple.com/guide/security/security-features-connecting-wireless-sec8a67fa93d/1/web/1#sec7e0184776) so that they can't access each other's memory. +Processors that handle networking are isolated via an [IOMMU](https://support.apple.com/guide/security/security-features-connecting-wireless-sec8a67fa93d/1/web/1#sec7e0184776) so that they can't access each other's memory. Overall, Apple does an excellent job with hardware security. Most Android OEMs could stand to learn from them. From 82737a6ed11901fb673e5ea269768fb70573d133 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Tue, 30 Sep 2025 02:41:04 -0500 Subject: [PATCH 38/68] wording Co-authored-by: redoomed1 Signed-off-by: fria <138676274+friadev@users.noreply.github.com> --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 437c7995..e0fdd412 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -92,7 +92,7 @@ In the EU, Apple was forced to allow [third-party app stores](https://developer. Android takes the opposite approach and lets you simply download and run apps from the internet. This gives you much more freedom as a user but could potentially open you up to more malicious apps, for example, apps that abuse [accessibility permissions](https://blog.pradeo.com/accessibility-services-mobile-analysis-malware) to gain deep access to your device. -The Google Play Store sets a strict [SDK level requirement](https://developer.android.com/google/play/requirements/target-sdk), but apps downloaded outside the Google Play Store have much more leniency. Sideloaded apps can target very old SDK levels, which means they won't have the same security restrictions as apps targeting newer SDK's. The biggest restriction that seems to exist in the OS preventing running older SDK's is if an app targets an SDK at or below Android 5.1 (!?) you'll get a warning message. For reference, Android 5 came out in 2014. +The Google Play Store sets a strict [SDK level requirement](https://developer.android.com/google/play/requirements/target-sdk), but apps downloaded outside the Google Play Store have much more leniency. Sideloaded apps can target very old SDK levels, which means they won't have the same security restrictions as apps targeting newer SDK's. The closest thing to a guardrail against running apps with older SDKs is a warning notification from the OS about an app targeting an SDK at or below Android 5.1 (!?). For reference, Android 5 came out in 2014. I think Android could stand to enforce a higher SDK level and simply refuse to run apps that target lower than say a few versions ago. There's no reason to support apps that think they're on Android 5. From da03a7191a5f4dfd0acc9f0c6d96ae67cfdde21c Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Tue, 30 Sep 2025 02:41:36 -0500 Subject: [PATCH 39/68] wording Co-authored-by: redoomed1 Signed-off-by: fria <138676274+friadev@users.noreply.github.com> --- blog/posts/ios-vs-android.md | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index e0fdd412..2c300fd9 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -94,9 +94,7 @@ Android takes the opposite approach and lets you simply download and run apps fr The Google Play Store sets a strict [SDK level requirement](https://developer.android.com/google/play/requirements/target-sdk), but apps downloaded outside the Google Play Store have much more leniency. Sideloaded apps can target very old SDK levels, which means they won't have the same security restrictions as apps targeting newer SDK's. The closest thing to a guardrail against running apps with older SDKs is a warning notification from the OS about an app targeting an SDK at or below Android 5.1 (!?). For reference, Android 5 came out in 2014. -I think Android could stand to enforce a higher SDK level and simply refuse to run apps that target lower than say a few versions ago. There's no reason to support apps that think they're on Android 5. - -GrapheneOS raises the minimum SDK from AOSP. +I think Android could stand to enforce a higher SDK level and simply refuse to run apps that target lower than say a few versions ago. There's no reason to support apps that think they're on Android 5. GrapheneOS, in line with its firm security posture, raises the minimum SDK from AOSP. Because of Android's support for third-party app stores, it's possible to use an app store with superior security to the Google Play Store. [Accrescent](https://accrescent.app) is just such an example. From d2be31d6e1511be90adc0dd513af618a7aadfe5e Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Tue, 30 Sep 2025 02:42:00 -0500 Subject: [PATCH 40/68] wording Co-authored-by: redoomed1 Signed-off-by: fria <138676274+friadev@users.noreply.github.com> --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 2c300fd9..e26a20ec 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -98,7 +98,7 @@ I think Android could stand to enforce a higher SDK level and simply refuse to r Because of Android's support for third-party app stores, it's possible to use an app store with superior security to the Google Play Store. [Accrescent](https://accrescent.app) is just such an example. -Accrescent allows for developers to control their own signing keys, and doesn't require an account, among other improvements. This is an improvement over the Google Play Store where Google controls the signing keys, and you need a Google account to use it. +Accrescent, among other features, allows for developers to control their own signing keys and doesn't require an account. This is an improvement over the Google Play Store where Google controls the signing keys and you need a Google account to download apps from it. ## Alternate OS Support From 96bc36d11966b97abb917eed08711b0e8ef47123 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Tue, 30 Sep 2025 02:43:43 -0500 Subject: [PATCH 41/68] wording Co-authored-by: redoomed1 Signed-off-by: fria <138676274+friadev@users.noreply.github.com> --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index e26a20ec..10d1b71b 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -106,7 +106,7 @@ Support for installing alternate operating systems isn't just important for user ### iOS -In order to install any apps or use many features on iOS, you need an [Apple Account](https://account.apple.com). Apple Accounts ask for your real name and require a phone number to use, on top of tying your app and other purchases to an account. While iOS is known to be privacy-friendly, Apple's [privacy policy](https://www.apple.com/legal/privacy/en-ww/) leaves a lot to be desired. +In order to install any apps or use many features on iOS, you need an [Apple Account](https://account.apple.com). Apple Accounts ask for your real name and require a phone number during account creation, on top of tying your app and other purchases to an account. While iOS is known to be privacy-friendly, Apple's [privacy policy](https://www.apple.com/legal/privacy/en-ww) leaves a lot to be desired. iOS doesn't allow you to unlock the bootloader to install another operating system. While [jailbreaking](https://en.wikipedia.org/wiki/IOS_jailbreaking) is possible, it requires exploiting your device and ultimately your security will be much worse. From d71dfc6e6d9fffc8f9fa550c5f3709f9de5372fc Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Tue, 30 Sep 2025 02:44:11 -0500 Subject: [PATCH 42/68] wording Co-authored-by: redoomed1 Signed-off-by: fria <138676274+friadev@users.noreply.github.com> --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 10d1b71b..d6e73caa 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -108,7 +108,7 @@ Support for installing alternate operating systems isn't just important for user In order to install any apps or use many features on iOS, you need an [Apple Account](https://account.apple.com). Apple Accounts ask for your real name and require a phone number during account creation, on top of tying your app and other purchases to an account. While iOS is known to be privacy-friendly, Apple's [privacy policy](https://www.apple.com/legal/privacy/en-ww) leaves a lot to be desired. -iOS doesn't allow you to unlock the bootloader to install another operating system. While [jailbreaking](https://en.wikipedia.org/wiki/IOS_jailbreaking) is possible, it requires exploiting your device and ultimately your security will be much worse. +iOS doesn't allow you to unlock the bootloader to install another OS. While [jailbreaking](https://en.wikipedia.org/wiki/IOS_jailbreaking) is possible, it requires exploiting your device and ultimately undermining your device's security. iOS should allow for fully unlocking and relocking the bootloader for alternate operating systems so that a version of iOS without any user data being sent to Apple can be installed. From 3880203a68d85cb44cee7db843cdf477b1234ad6 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Tue, 30 Sep 2025 02:44:53 -0500 Subject: [PATCH 43/68] wording Co-authored-by: redoomed1 Signed-off-by: fria <138676274+friadev@users.noreply.github.com> --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index d6e73caa..4f0618a6 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -130,7 +130,7 @@ The open nature of Android is ruined a bit by most of the OEMs, like [Samsung](h GrapheneOS is probably the best example of what an alternate OS can achieve. They've made [significant security improvements](https://grapheneos.org/features) over the default Pixel OS and AOSP. -GrapheneOS utilizes hardware features like MTE, which is locked behind [Advanced Protection](https://support.google.com/accounts/answer/9764949?hl=en) normally, by default and with significantly [more coverage](https://x.com/GrapheneOS/status/1965810573066768865#m). +For example, whereas MTE is locked behind [Advanced Protection](https://support.google.com/accounts/answer/9764949?hl=en) on the stock Pixel OS, GrapheneOS utilizes the hardware feature by default and with significantly [more coverage](https://x.com/GrapheneOS/status/1965810573066768865#m). They also disable USB at the [hardware level](https://grapheneos.org/features#usb-c-port-and-pogo-pins-control). This is a demonstrable security improvement, as forensics companies like [Cellebrite](https://discuss.grapheneos.org/d/14344-cellebrite-premium-july-2024-documentation) have leaked documentation showing they're not able to get into GrapheneOS devices above a 2022 patch level. From ad24f5e9aa505f67d196c4f68c1670c0f17d3387 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Tue, 30 Sep 2025 02:45:20 -0500 Subject: [PATCH 44/68] wording Co-authored-by: redoomed1 Signed-off-by: fria <138676274+friadev@users.noreply.github.com> --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 4f0618a6..ca60bc2d 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -132,7 +132,7 @@ GrapheneOS is probably the best example of what an alternate OS can achieve. The For example, whereas MTE is locked behind [Advanced Protection](https://support.google.com/accounts/answer/9764949?hl=en) on the stock Pixel OS, GrapheneOS utilizes the hardware feature by default and with significantly [more coverage](https://x.com/GrapheneOS/status/1965810573066768865#m). -They also disable USB at the [hardware level](https://grapheneos.org/features#usb-c-port-and-pogo-pins-control). This is a demonstrable security improvement, as forensics companies like [Cellebrite](https://discuss.grapheneos.org/d/14344-cellebrite-premium-july-2024-documentation) have leaked documentation showing they're not able to get into GrapheneOS devices above a 2022 patch level. +GrapheneOS also disables USB at the [hardware level](https://grapheneos.org/features#usb-c-port-and-pogo-pins-control). This is a demonstrable security improvement, as forensics companies like [Cellebrite](https://discuss.grapheneos.org/d/14344-cellebrite-premium-july-2024-documentation) have leaked documentation showing they're not able to get into GrapheneOS devices above a 2022 patch level. The ability to unlock the bootloader on Android devices is a huge boon for security research as well. From 9fe5005ad8706547f80ff8be830ede0c573aa4e7 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Tue, 30 Sep 2025 02:45:59 -0500 Subject: [PATCH 45/68] wording Co-authored-by: redoomed1 Signed-off-by: fria <138676274+friadev@users.noreply.github.com> --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index ca60bc2d..8406bf9c 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -146,7 +146,7 @@ iOS has historically been ahead of AOSP in terms of the permissions it offers. iOS's [paste permission](https://developer.apple.com/documentation/uikit/uipasteboard) prevents apps from nefariously reading data from your clipboard without your permission, something AOSP lacks still. -Since iOS 13, apps need to go through the [system file picker](https://developer.apple.com/documentation/uikit/providing-access-to-directories) and are only granted access to the specific files the user allows via a security-scoped URL, they don't gain access to the full filesystem like apps can on [Android](https://developer.android.com/training/data-storage/manage-all-files#:~:text=Android%20provides%20a%20special%20app%20access%20called%20all%2Dfiles%20access%20for%20these%20situations.). +Since iOS 13, when apps request file access, apps need to go through the [system file picker](https://developer.apple.com/documentation/uikit/providing-access-to-directories) and are only granted access to the specific files the user allows via a security-scoped URL. They don't gain access to the full filesystem like apps can on [Android](https://developer.android.com/training/data-storage/manage-all-files#:~:text=Android%20provides%20a%20special%20app%20access%20called%20all%2Dfiles%20access%20for%20these%20situations.). iOS added the [Local Network](https://developer.apple.com/documentation/technotes/tn3179-understanding-local-network-privacy) permission in iOS 14, preventing apps from accessing other devices on your local network such as other phones or computers, maybe even network drives with sensitive data on them. Android later [added this permission](https://developer.android.com/privacy-and-security/local-network-permission) in Android 16, albeit currently as opt-in for developers. From 4a10a726bdc03a2b3887e176b6b2b5fcf15b2778 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Tue, 30 Sep 2025 02:46:41 -0500 Subject: [PATCH 46/68] wording --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 8406bf9c..cbef7017 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -146,7 +146,7 @@ iOS has historically been ahead of AOSP in terms of the permissions it offers. iOS's [paste permission](https://developer.apple.com/documentation/uikit/uipasteboard) prevents apps from nefariously reading data from your clipboard without your permission, something AOSP lacks still. -Since iOS 13, when apps request file access, apps need to go through the [system file picker](https://developer.apple.com/documentation/uikit/providing-access-to-directories) and are only granted access to the specific files the user allows via a security-scoped URL. They don't gain access to the full filesystem like apps can on [Android](https://developer.android.com/training/data-storage/manage-all-files#:~:text=Android%20provides%20a%20special%20app%20access%20called%20all%2Dfiles%20access%20for%20these%20situations.). +Since iOS 13, when apps request file access, they need to go through the [system file picker](https://developer.apple.com/documentation/uikit/providing-access-to-directories) and are only granted access to the specific files the user allows via a security-scoped URL. They don't gain access to the full filesystem like apps can on [Android](https://developer.android.com/training/data-storage/manage-all-files#:~:text=Android%20provides%20a%20special%20app%20access%20called%20all%2Dfiles%20access%20for%20these%20situations.). iOS added the [Local Network](https://developer.apple.com/documentation/technotes/tn3179-understanding-local-network-privacy) permission in iOS 14, preventing apps from accessing other devices on your local network such as other phones or computers, maybe even network drives with sensitive data on them. Android later [added this permission](https://developer.android.com/privacy-and-security/local-network-permission) in Android 16, albeit currently as opt-in for developers. From 6397966a1dd2605ee685bb489864569e7eeb7380 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Wed, 5 Nov 2025 08:44:57 -0600 Subject: [PATCH 47/68] add ios kernel --- blog/posts/ios-vs-android.md | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index cbef7017..c5830bc3 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -40,6 +40,34 @@ Many open-source, custom AOSP-based operating systems actually reduce security f One problem custom Android operating systems face is the inherent issue of being [downstream](https://en.wikipedia.org/wiki/Downstream_(software_development)) of AOSP, which means third-party operating systems must wait for the upstream project to ship patches and updates. In this case, AOSP-based operating systems are [at the whim of Google](https://x.com/grapheneos/status/1964561043906048183) for timely security patches and updates, which is not ideal. +## Kernel + +The kernel is the low-level code that controls just about everything that happens in an operating system. As you can imagine, a kernel exploit could give an attacker highly privileged access to your system, so the kernel should be as locked down and as minimal as possible, with it being written in a memory-safe language like Rust. Unfortunately, operating systems until now have mostly resorted to a monolithic kernel design, which puts all duties of the operating system like memory management, device drivers, etc are in the kernel proper. This allows for more performance and less complexity but much more attack surface. + +In contrast, a microkernel design puts as much as possible outside the kernel, which reduces the possible attack surface but increases the complexity and can have a performance hit. + +### iOS + +iOS uses their own open source XNU kernel for their operating systems. It's an interesting design as Apple originally took the [Mach](https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/KernelProgramming/Mach/Mach.html) microkernel and combined it with code from the monolithic [FreeBSD](https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/KernelProgramming/BSD/BSD.html#//apple_ref/doc/uid/TP30000905-CH214-TPXREF101) kernel to create the hybrid [XNU](https://github.com/apple-oss-distributions/xnu) kernel. + +This leaves XNU in an interesting place where it's doesn't have the full attack surface of a monolithic kernel nor the full security of a microkernel, since + +>in OS X, Mach is linked with other kernel components into a single kernel address space. This is primarily for performance; it is much faster to make a direct call between linked components than it is to send messages or do remote procedure calls (RPC) between separate tasks. This modular structure results in a more robust and extensible system than a monolithic kernel would allow, without the performance penalty of a pure microkernel. + +It's a bit frustrating to know that the only reason they didn't go with a full microkernel design seems to be performance; I'd like to think that nowadays computers are fast enough that it wouldn't matter so much. Apple should persue a microkernel design as soon as possible to avoid kernel exploits. + +Apple has made good progress in pushing for things like drivers to run in userspace rather than kernelspace through [System Extensions](https://developer.apple.com/documentation/systemextensions), which replace [kernel extensions](https://support.apple.com/guide/security/securely-extending-the-kernel-sec8e454101b/web) that used to run in the kernel. This is a promising development and I think it represents a desire from Apple to move toward a microkernel. + +### Exclaves + +Apple as seemingly been working on a new feature inside their kernel called "[exclaves](https://www.theregister.com/2025/03/08/kernel_sanders_apple_rearranges_xnu/)" that appear to isolate and protect components of the kernel from the rest of the kernel. + +An interesting example of how this is being used is to [secure](https://theapplewiki.com/wiki/Secure_Indicator_Light) the camera and microphone indicator lights so that a compromise of the kernel won't mean a compromise of the indicator lights. + +There are references to a new "Secure Kernel" with a version string for "cL4" which may be a reference to the secure [seL4](https://sel4.systems) microkernel, possibly hinting even more at Apple's long-term ambitions. + +This is great news, I hope we hear more about exclaves in the future, especially via an official announcement from Apple and not from digging through code. + ## Hardware Hardware is vital to security. Modern smartphones pose a challenge with lots of processors and components, each with their own firmware and potential security vulnerabilities. It's important to lock down these components as much as possible. From 25f8665695c236d37b96bf0c5a1443c7b81402fc Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Wed, 5 Nov 2025 09:02:54 -0600 Subject: [PATCH 48/68] add memory safety --- blog/posts/ios-vs-android.md | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index c5830bc3..11dbc105 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -68,6 +68,16 @@ There are references to a new "Secure Kernel" with a version string for "cL4" wh This is great news, I hope we hear more about exclaves in the future, especially via an official announcement from Apple and not from digging through code. +#### Memory Safety + +Unfortunately, the XNU kernel is still mostly written in C. This is a problem for any piece of software but *especially* so for the kernel. I really hope Apple makes an effort to start replacing the internals with a memory-safe language. + +[Embedded Swift](https://docs.swift.org/embedded/documentation/embedded/introduction) is a low level programming language based on [Swift](https://www.swift.org) that aims to preserve the memory safety while being more suitable for low-level programs like embedded controllers or system kernels. While it's still experimental, I'll be watching. Apple has switch some of their servers to Swift to massive benefit and they've been switching more of their [iOS apps](https://blog.timac.org/2024/1208-state-of-swift-and-swiftui-ios18/) to Swift, so I believe they will eventually work on switching the rest of their code to Swift in due time. + +### Android + +Android uses the Linux kernel, a monolithic kernel that's a favorite of sysadmins and open source enthusiasts alike. Unfortunately, the monolithic nature of Linux makes it a [massive attack surface](https://xcancel.com/GrapheneOS/status/1952583510059057188#m) for Android. + ## Hardware Hardware is vital to security. Modern smartphones pose a challenge with lots of processors and components, each with their own firmware and potential security vulnerabilities. It's important to lock down these components as much as possible. From 8a481d322da7e970fdd6eb4dad88bcecf56a53a6 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Wed, 5 Nov 2025 09:16:29 -0600 Subject: [PATCH 49/68] add memory safety for linux --- blog/posts/ios-vs-android.md | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 11dbc105..cd6d7dfc 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -76,7 +76,15 @@ Unfortunately, the XNU kernel is still mostly written in C. This is a problem fo ### Android -Android uses the Linux kernel, a monolithic kernel that's a favorite of sysadmins and open source enthusiasts alike. Unfortunately, the monolithic nature of Linux makes it a [massive attack surface](https://xcancel.com/GrapheneOS/status/1952583510059057188#m) for Android. +Android uses the Linux kernel, a monolithic kernel that's a favorite of sysadmins and open source enthusiasts alike. Unfortunately, the monolithic nature of Linux makes it a [massive attack surface](https://xcancel.com/GrapheneOS/status/1923966381965394221#m) for Android. + +GrapheneOS even considers the Linux kernel to be their [main weakness](https://xcancel.com/GrapheneOS/status/1828148094661198105#m) at the moment, and have expressed a desire to switch to a microkernel at some point in the future. + +### Memory Safety + +The Linux kernel is mainly written in C, a memory-unsafe language. + +The [Rust for Linux](https://rust-for-linux.com) has successfully added support for Rust in Linux, and they're looking to increase the amount of memory safe code, so definitely watch out for that. ## Hardware From da572b2a624f2983b6667fb58b1e0f8b286364de Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Wed, 5 Nov 2025 09:17:43 -0600 Subject: [PATCH 50/68] replace facebook with samsung notes --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index cd6d7dfc..d27962e5 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -32,7 +32,7 @@ I'd like to see Apple release the source code of its entire OS in order to foste The beating heart of Android is the [Android Open Source Project](https://source.android.com) (AOSP). AOSP is essentially a complete, open-source mobile OS on its own. Android was designed from the beginning to be used by lots of different companies for each of their own mobile phone offerings, so the open nature is useful toward that goal. -However, AOSP is only a bare-bones OS. OEMs are expected to add their own proprietary components to make a custom user experience specific to their brand. This is why most Android phones you buy are pre-installed with proprietary software like Facebook and other OEM software. Companies that sell Android phones mainly use AOSP as a secure base to then run on their phones with proprietary drivers and a custom Android OS. While the openness of AOSP is great, the OEMs producing the phones ultimately ruin it. +However, AOSP is only a bare-bones OS. OEMs are expected to add their own proprietary components to make a custom user experience specific to their brand. This is why most Android phones you buy are pre-installed with proprietary software like [Samsung Notes](https://www.samsung.com/ae/apps/samsung-notes/) and other OEM software. Companies that sell Android phones mainly use AOSP as a secure base to then run on their phones with proprietary drivers and a custom Android OS. While the openness of AOSP is great, the OEMs producing the phones ultimately ruin it. Because AOSP is open source though, non-OEM third parties such as [GrapheneOS](https://grapheneos.org) have made their own fully open-source Android OS. Unlike stock Android operating systems, GrapheneOS supports [reproducible builds](https://grapheneos.org/build#reproducible-builds). From e0f177b35383bae1f5e97b529a5e8d23ee92fba4 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Fri, 7 Nov 2025 08:10:37 -0600 Subject: [PATCH 51/68] fix typo --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index d27962e5..fe008508 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -84,7 +84,7 @@ GrapheneOS even considers the Linux kernel to be their [main weakness](https://x The Linux kernel is mainly written in C, a memory-unsafe language. -The [Rust for Linux](https://rust-for-linux.com) has successfully added support for Rust in Linux, and they're looking to increase the amount of memory safe code, so definitely watch out for that. +The [Rust for Linux](https://rust-for-linux.com) project has successfully added support for Rust in Linux, and they're looking to increase the amount of memory safe code, so definitely watch out for that. ## Hardware From d78aa38cc145a43d8024060b1eb9c33132ec16a7 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Fri, 7 Nov 2025 08:13:03 -0600 Subject: [PATCH 52/68] add swift on server link --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index fe008508..4f3d74d4 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -72,7 +72,7 @@ This is great news, I hope we hear more about exclaves in the future, especially Unfortunately, the XNU kernel is still mostly written in C. This is a problem for any piece of software but *especially* so for the kernel. I really hope Apple makes an effort to start replacing the internals with a memory-safe language. -[Embedded Swift](https://docs.swift.org/embedded/documentation/embedded/introduction) is a low level programming language based on [Swift](https://www.swift.org) that aims to preserve the memory safety while being more suitable for low-level programs like embedded controllers or system kernels. While it's still experimental, I'll be watching. Apple has switch some of their servers to Swift to massive benefit and they've been switching more of their [iOS apps](https://blog.timac.org/2024/1208-state-of-swift-and-swiftui-ios18/) to Swift, so I believe they will eventually work on switching the rest of their code to Swift in due time. +[Embedded Swift](https://docs.swift.org/embedded/documentation/embedded/introduction) is a low level programming language based on [Swift](https://www.swift.org) that aims to preserve the memory safety of Swift while being more suitable for low-level programs like embedded controllers or system kernels. While it's still experimental, I'll be watching. Apple has [switched](https://www.swift.org/blog/swift-at-apple-migrating-the-password-monitoring-service-from-java/) some of their servers to Swift to massive benefit and they've been switching more of their [iOS apps](https://blog.timac.org/2024/1208-state-of-swift-and-swiftui-ios18/) to Swift, so I believe they will eventually work on switching the rest of their code to Swift in due time. ### Android From 948a7427a849d2e651a96a1c75587d3b9c381ce3 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Fri, 7 Nov 2025 08:17:31 -0600 Subject: [PATCH 53/68] remove unnecessary line --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 4f3d74d4..0613d364 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -18,7 +18,7 @@ Both Android and iOS run on the vast majority of our mobile devices, meaning the ## Source Model -One of the most glaring differences is the source model of each operating system: iOS is *mostly* closed source while Android is *mostly* open source. Continue reading to learn the implications of this difference. +One of the most glaring differences is the source model of each operating system: iOS is *mostly* closed source while Android is *mostly* open source. ### iOS From 78f32cf3a15140d5568157babb9ef9e8aaf54ef6 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Fri, 7 Nov 2025 08:43:11 -0600 Subject: [PATCH 54/68] add android release cycle notes --- blog/posts/ios-vs-android.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 0613d364..aa246431 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -40,6 +40,8 @@ Many open-source, custom AOSP-based operating systems actually reduce security f One problem custom Android operating systems face is the inherent issue of being [downstream](https://en.wikipedia.org/wiki/Downstream_(software_development)) of AOSP, which means third-party operating systems must wait for the upstream project to ship patches and updates. In this case, AOSP-based operating systems are [at the whim of Google](https://x.com/grapheneos/status/1964561043906048183) for timely security patches and updates, which is not ideal. +Google doesn't make Android code fully open source for the full development cycle; instead they have an [internal](https://source.android.com/docs/setup/contribute/release-lifecycle) branch that's not accessible to the public which they then release to the public when they deem it's ready. + ## Kernel The kernel is the low-level code that controls just about everything that happens in an operating system. As you can imagine, a kernel exploit could give an attacker highly privileged access to your system, so the kernel should be as locked down and as minimal as possible, with it being written in a memory-safe language like Rust. Unfortunately, operating systems until now have mostly resorted to a monolithic kernel design, which puts all duties of the operating system like memory management, device drivers, etc are in the kernel proper. This allows for more performance and less complexity but much more attack surface. From ed92a35baa5d58b9073839344456c4b0f08738b9 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Fri, 7 Nov 2025 08:47:31 -0600 Subject: [PATCH 55/68] elaborate on android release cycle --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index aa246431..86dc3ce9 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -40,7 +40,7 @@ Many open-source, custom AOSP-based operating systems actually reduce security f One problem custom Android operating systems face is the inherent issue of being [downstream](https://en.wikipedia.org/wiki/Downstream_(software_development)) of AOSP, which means third-party operating systems must wait for the upstream project to ship patches and updates. In this case, AOSP-based operating systems are [at the whim of Google](https://x.com/grapheneos/status/1964561043906048183) for timely security patches and updates, which is not ideal. -Google doesn't make Android code fully open source for the full development cycle; instead they have an [internal](https://source.android.com/docs/setup/contribute/release-lifecycle) branch that's not accessible to the public which they then release to the public when they deem it's ready. +Google doesn't make Android code fully open source for the full development cycle; instead they have an [internal](https://source.android.com/docs/setup/contribute/release-lifecycle) branch that's not accessible to the public which they then release to the public when they deem it's ready, which means that any patches in this internal branch are not accessible to any project that exclusively relies on AOSP code. ## Kernel From 3652879d8610622e83722e827809540fa8dbec37 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Fri, 7 Nov 2025 08:49:21 -0600 Subject: [PATCH 56/68] fix typo --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 86dc3ce9..0233d0e5 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -262,7 +262,7 @@ The browser is a major way users are exposed to malware. Your browser runs untru ### iOS -On iOS, you're [locked to using WebKit](https://developer.apple.com/app-store/review/guidelines/#:~:text=Apps%20that%20browse%20the%20web%20must%20use%20the%20appropriate%20WebKit%20framework%20and%20WebKit%20JavaScript.). Any other browesr you install is essentially just a reskin of Safari. +On iOS, you're [locked to using WebKit](https://developer.apple.com/app-store/review/guidelines/#:~:text=Apps%20that%20browse%20the%20web%20must%20use%20the%20appropriate%20WebKit%20framework%20and%20WebKit%20JavaScript.). Any other browser you install is essentially just a reskin of Safari. Apple did allow [alternate browser engines](https://developer.apple.com/support/alternative-browser-engines/) in the EU, but in other regions you're still locked to using WebKit. From 6dd63b521780fcec924fa279988fcdfb55c4c08d Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Fri, 7 Nov 2025 08:52:04 -0600 Subject: [PATCH 57/68] add mention of no alternate browser engines on ios --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 0233d0e5..2beb721c 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -264,7 +264,7 @@ The browser is a major way users are exposed to malware. Your browser runs untru On iOS, you're [locked to using WebKit](https://developer.apple.com/app-store/review/guidelines/#:~:text=Apps%20that%20browse%20the%20web%20must%20use%20the%20appropriate%20WebKit%20framework%20and%20WebKit%20JavaScript.). Any other browser you install is essentially just a reskin of Safari. -Apple did allow [alternate browser engines](https://developer.apple.com/support/alternative-browser-engines/) in the EU, but in other regions you're still locked to using WebKit. +Apple did allow [alternate browser engines](https://developer.apple.com/support/alternative-browser-engines/) in the EU, but in other regions you're still locked to using WebKit. However, there have yet to be any [alternate browser engines](https://www.macobserver.com/news/15-months-later-iphone-users-still-cant-choose-a-real-browser/) available that I could find. While Safari does offer good [privacy features](https://webkit.org/blog/15697/private-browsing-2-0/), it's lacking some important security protections that other browsers have like [site isolation](https://docs.webkit.org/Deep%20Dive/SiteIsolation.html#finding-what-needs-to-be-done), which they are currently working on implementing but it will be some time before it's done. From 1cf5a7adae1c7c5862785cc0eb670917f7c72892 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Fri, 7 Nov 2025 09:03:27 -0600 Subject: [PATCH 58/68] add app fingerprinting --- blog/posts/ios-vs-android.md | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 2beb721c..6246a71b 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -272,5 +272,13 @@ Locking users out of other browsers stifles competition and user freedom, not to Apple should open up their ecosystem to allow for alternate browser engines globally instead of just in the EU. +## App Fingerprinting + +Just like in a browser, it's possible for an to fingerprint your device and identify you as the same person. It's not as much of a concern usually as on browsers since apps tend to keep persistent data while they're installed anyway, but it's something to keep in mind. + +### iOS + + + ## Optional App Hardening From a935afe1a3bca16249ab6303c6af1dd7a787d174 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Fri, 7 Nov 2025 09:39:29 -0600 Subject: [PATCH 59/68] add info about ios fingerprinting --- blog/posts/ios-vs-android.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 6246a71b..2827ddb3 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -278,7 +278,11 @@ Just like in a browser, it's possible for an to fingerprint your device and iden ### iOS +It's difficult to know all the exact methods used for fingerpinting as fingerprinting services like [fingerprint.com](https://fingerprint.com) are tight-lipped on a lot of it. They don't want anyone knowing how they do it so operating systems can patch those vectors. However, we can use their apps and test how effective they are, and look at what they make visible to us. +Fingerprint offers an iOS [demo app](https://apps.apple.com/en/app/fingerprint-pro/id1644105278) so you can see how well it works. + +Fingerprinting may not be all that necessary however since Apple's [IDFV](https://developer.apple.com/documentation/uikit/uidevice/identifierforvendor) by design allows apps by the same vendor to identify the same device. It changes when all apps by that vendor are deleted but in my testing, I got the same identifier in their demo app even after deleting and reinstalling the apps. Fingerprint claims that the idnetifier will be the same after a device restart, after deleting and reinstalling the app, after installing a provisioning profile, after jailbreaking, after lockdown mode is enabled, and after reseting the device settings to their default values. The only case when it will change is after a full factory reset. ## Optional App Hardening From e8cc8d87532d72b3e4fa6990ea03502f50019cb7 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Fri, 7 Nov 2025 09:45:38 -0600 Subject: [PATCH 60/68] add more ios fingeprinting info --- blog/posts/ios-vs-android.md | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 2827ddb3..b604d529 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -284,5 +284,11 @@ Fingerprint offers an iOS [demo app](https://apps.apple.com/en/app/fingerprint-p Fingerprinting may not be all that necessary however since Apple's [IDFV](https://developer.apple.com/documentation/uikit/uidevice/identifierforvendor) by design allows apps by the same vendor to identify the same device. It changes when all apps by that vendor are deleted but in my testing, I got the same identifier in their demo app even after deleting and reinstalling the apps. Fingerprint claims that the idnetifier will be the same after a device restart, after deleting and reinstalling the app, after installing a provisioning profile, after jailbreaking, after lockdown mode is enabled, and after reseting the device settings to their default values. The only case when it will change is after a full factory reset. +It will also try to detect if your device is jailbroken, or has been factory reset. + +I think it's clear that Apple draws the line at the same vendor having the same device ID when their apps are installed, but apps are clearly still able to identify you even then. + +Apple's [IDFA](https://developer.apple.com/documentation/adsupport/asidentifiermanager/advertisingidentifier) is meant to provide this type of identifiers across vendors over time on the same device only optionally through the [App Tracking Transparency](https://developer.apple.com/documentation/AppTrackingTransparency) framework. Clearly this level of fingerprinting is a violation of Apple's intentions for the identifiers on iOS and I hope they can address whatever is being used as a fingerprinting vector here. + ## Optional App Hardening From 88e94a3b20d0492dab7fa69ea21ce2b841ae8ddc Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Sun, 9 Nov 2025 07:19:19 -0600 Subject: [PATCH 61/68] android app fingerprinting --- blog/posts/ios-vs-android.md | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index b604d529..d7f0bd2b 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -290,5 +290,13 @@ I think it's clear that Apple draws the line at the same vendor having the same Apple's [IDFA](https://developer.apple.com/documentation/adsupport/asidentifiermanager/advertisingidentifier) is meant to provide this type of identifiers across vendors over time on the same device only optionally through the [App Tracking Transparency](https://developer.apple.com/documentation/AppTrackingTransparency) framework. Clearly this level of fingerprinting is a violation of Apple's intentions for the identifiers on iOS and I hope they can address whatever is being used as a fingerprinting vector here. +### Android + +Android app fingerprinting is a well-known problem, with multiple possible vectors. Apps are able to see all other installed apps and the date and time they were updated, for example. A GrapheneOS [forum discussion](https://discuss.grapheneos.org/d/17118-identifiers-across-private-space-and-profiles/4) lays out a few ways app fingerprinting can work, even across profiles. + +FingerprintJS supports [Android devices](https://dev.fingerprint.com/docs/native-android-integration) and claims it can identify the same device after it restarts, after app data/cache is cleared, after the app is deleted and reinstalled, after a factory reset, even if the app is installed in different profiles or user accounts. This is particularly upsetting since many people use Android profiles to separate out their activities. + +I hope Google will see app fingerprinting as a real problem and take steps to mitigate it, especially between factory resets and profiles. I feel that those are the most important boundaries to uphold: a factory reset should be a clean slate, and a separate profile should be almost like a separate phone. + ## Optional App Hardening From 90d5a01f52a916c1be4708d834fba9e0d7625bad Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Sun, 9 Nov 2025 07:36:20 -0600 Subject: [PATCH 62/68] fix typo --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index d7f0bd2b..85881d6d 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -228,7 +228,7 @@ Support for separate user profiles allows for strong separation of activities, s ### iOS -iOS doesn't allow for separate profiles. This is a major detriment on iOS as Android does support separate profiles, each encrypted with a separate encryption key.. +iOS doesn't allow for separate profiles. This is a major detriment on iOS as Android does support separate profiles, each encrypted with a separate encryption key. iOS could benefit massively from introducing multiple user profiles. Apple has already implemented the feature on [iPadOS](https://support.apple.com/guide/deployment/shared-ipad-overview-dep9a34c2ba2/web) but requires the iPad to be supervised. From b1d115df368285b85c447bdf35656e4c36ed561d Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Sun, 9 Nov 2025 07:44:59 -0600 Subject: [PATCH 63/68] add play protect info --- blog/posts/ios-vs-android.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 85881d6d..f32181a8 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -140,6 +140,8 @@ In the EU, Apple was forced to allow [third-party app stores](https://developer. Android takes the opposite approach and lets you simply download and run apps from the internet. This gives you much more freedom as a user but could potentially open you up to more malicious apps, for example, apps that abuse [accessibility permissions](https://blog.pradeo.com/accessibility-services-mobile-analysis-malware) to gain deep access to your device. +Google [Play Protect](https://developers.google.com/android/play-protect) is a built-in anti-malware in many Android devices that's meant to protect you against malicious apps, so it's not like you're completely defenseless. In my opinion, though, anti-malware isn't the correct solution. Hardening the sandbox with tighter restrictions and more permissions, such as the user-facing [network permission](https://grapheneos.org/features#network-permission-toggle) in GrapheneOS, is the best approach. + The Google Play Store sets a strict [SDK level requirement](https://developer.android.com/google/play/requirements/target-sdk), but apps downloaded outside the Google Play Store have much more leniency. Sideloaded apps can target very old SDK levels, which means they won't have the same security restrictions as apps targeting newer SDK's. The closest thing to a guardrail against running apps with older SDKs is a warning notification from the OS about an app targeting an SDK at or below Android 5.1 (!?). For reference, Android 5 came out in 2014. I think Android could stand to enforce a higher SDK level and simply refuse to run apps that target lower than say a few versions ago. There's no reason to support apps that think they're on Android 5. GrapheneOS, in line with its firm security posture, raises the minimum SDK from AOSP. From 27d862873085336c3a69bad3980b931a9a4aea21 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Sun, 9 Nov 2025 07:53:01 -0600 Subject: [PATCH 64/68] add advanced protection info --- blog/posts/ios-vs-android.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index f32181a8..21a13752 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -142,6 +142,8 @@ Android takes the opposite approach and lets you simply download and run apps fr Google [Play Protect](https://developers.google.com/android/play-protect) is a built-in anti-malware in many Android devices that's meant to protect you against malicious apps, so it's not like you're completely defenseless. In my opinion, though, anti-malware isn't the correct solution. Hardening the sandbox with tighter restrictions and more permissions, such as the user-facing [network permission](https://grapheneos.org/features#network-permission-toggle) in GrapheneOS, is the best approach. +Google, in a slightly bizarre twist, locks users to only being able to download apps from the Play Store if they enable [Advanced Protection](https://support.google.com/accounts/answer/9764949?hl=en), so if you want the highest security on a stock Android device, you will have to sacrifice sideloading. + The Google Play Store sets a strict [SDK level requirement](https://developer.android.com/google/play/requirements/target-sdk), but apps downloaded outside the Google Play Store have much more leniency. Sideloaded apps can target very old SDK levels, which means they won't have the same security restrictions as apps targeting newer SDK's. The closest thing to a guardrail against running apps with older SDKs is a warning notification from the OS about an app targeting an SDK at or below Android 5.1 (!?). For reference, Android 5 came out in 2014. I think Android could stand to enforce a higher SDK level and simply refuse to run apps that target lower than say a few versions ago. There's no reason to support apps that think they're on Android 5. GrapheneOS, in line with its firm security posture, raises the minimum SDK from AOSP. From e0e0ae1149e1ac8f452bc8dfbb04eda8636b3427 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Sun, 9 Nov 2025 08:16:48 -0600 Subject: [PATCH 65/68] add apple's app store whitepaper --- blog/posts/ios-vs-android.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 21a13752..be23af0a 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -128,6 +128,8 @@ Android and iOS have very different approaches in terms of downloading and acqui iOS restricts app downloads to their own App Store. Apple claims this is for security purposes, but it restricts user freedom and makes it possible for Apple to [censor](https://9to5mac.com/2024/09/28/apple-cooperating-with-russia-to-remove-vpn-apps-from-app-store) apps in certain regions. +Apple has a [whitepaper](https://www.apple.com/privacy/docs/Building_a_Trusted_Ecosystem_for_Millions_of_Apps.pdf) explaining why they believe restricting to just the App Store is the best approach to security. Unfortuantely, malicious and fruadulent apps [bypass](https://techcrunch.com/2025/10/09/sora-copycats-flooded-apples-app-store-and-some-still-remain/) Apple's App Store review regularly. Automated and human review can only do so much against an onslaught of malicious apps, so I think that a better approach is to design the system to disallow apps from having access to as much as possible and providing users with highly secure devices to prevent malware as much as possible. + The App Store does enforce certain [security](https://support.apple.com/guide/security/about-app-store-security-secb8f887a15/1/web/1) properties, mainly through the App Review process. This process can't catch everything though, and [malware](https://securelist.com/sparkcat-stealer-in-app-store-and-google-play/115385) still slips through the cracks. The lack of third-party app store support means that it's not possible to use an app store with better security properties than the Apple App Store. For example, apps in the App Store have Apple's DRM, which makes reproducible builds [impossible](https://github.com/signalapp/Signal-iOS/issues/641#:~:text=So%20while%20truly%20reproducible%20builds%20are%20not%20possible). If one wanted to use an app store without this security regression, they'd be out of luck. From d6d7dbcdc2b636cf68066d7ea52a6425fbeaaf8a Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Sun, 9 Nov 2025 08:19:18 -0600 Subject: [PATCH 66/68] add play store criticism --- blog/posts/ios-vs-android.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index be23af0a..56f70004 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -146,6 +146,8 @@ Google [Play Protect](https://developers.google.com/android/play-protect) is a b Google, in a slightly bizarre twist, locks users to only being able to download apps from the Play Store if they enable [Advanced Protection](https://support.google.com/accounts/answer/9764949?hl=en), so if you want the highest security on a stock Android device, you will have to sacrifice sideloading. +As I pointed out with the Apple App Store, malicious apps [bypass](https://www.forbes.com/sites/daveywinder/2025/03/18/60-million-malicious-google-play-downloads-as-331-apps-bypass-security/) the Play Store review all the time. The idea that the Play Store review process is a viable defense against malware is misguided and can put users at risk in my opinion. Google needs to enforce security on the OS level as much as possible to avoid malicious apps, not rely on Play Store review. + The Google Play Store sets a strict [SDK level requirement](https://developer.android.com/google/play/requirements/target-sdk), but apps downloaded outside the Google Play Store have much more leniency. Sideloaded apps can target very old SDK levels, which means they won't have the same security restrictions as apps targeting newer SDK's. The closest thing to a guardrail against running apps with older SDKs is a warning notification from the OS about an app targeting an SDK at or below Android 5.1 (!?). For reference, Android 5 came out in 2014. I think Android could stand to enforce a higher SDK level and simply refuse to run apps that target lower than say a few versions ago. There's no reason to support apps that think they're on Android 5. GrapheneOS, in line with its firm security posture, raises the minimum SDK from AOSP. From dbd63640ab1eea3d985cef1923e02b0c241b72a6 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Sun, 9 Nov 2025 08:21:56 -0600 Subject: [PATCH 67/68] add more app store details --- blog/posts/ios-vs-android.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index 56f70004..b723e2d0 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -128,7 +128,7 @@ Android and iOS have very different approaches in terms of downloading and acqui iOS restricts app downloads to their own App Store. Apple claims this is for security purposes, but it restricts user freedom and makes it possible for Apple to [censor](https://9to5mac.com/2024/09/28/apple-cooperating-with-russia-to-remove-vpn-apps-from-app-store) apps in certain regions. -Apple has a [whitepaper](https://www.apple.com/privacy/docs/Building_a_Trusted_Ecosystem_for_Millions_of_Apps.pdf) explaining why they believe restricting to just the App Store is the best approach to security. Unfortuantely, malicious and fruadulent apps [bypass](https://techcrunch.com/2025/10/09/sora-copycats-flooded-apples-app-store-and-some-still-remain/) Apple's App Store review regularly. Automated and human review can only do so much against an onslaught of malicious apps, so I think that a better approach is to design the system to disallow apps from having access to as much as possible and providing users with highly secure devices to prevent malware as much as possible. +Apple has a [whitepaper](https://www.apple.com/privacy/docs/Building_a_Trusted_Ecosystem_for_Millions_of_Apps.pdf) explaining why they believe restricting to just the App Store is the best approach to security. Unfortuantely, malicious and fruadulent apps [bypass](https://techcrunch.com/2025/10/09/sora-copycats-flooded-apples-app-store-and-some-still-remain/) Apple's App Store review regularly. Automated and human review can only do so much against an onslaught of malicious apps, so I think that a better approach is to design the system to disallow apps from having access to as much as possible and providing users with highly secure devices to prevent malware as much as possible. In the same whitepaper, Apple outlines some things they've done to combat malicious apps in a more systemic way such as SDK package signing. In contrast to their claims, the EU's DMA seems to have spurred them to improve security on iOS in several ways while also increasing user freedom. The App Store does enforce certain [security](https://support.apple.com/guide/security/about-app-store-security-secb8f887a15/1/web/1) properties, mainly through the App Review process. This process can't catch everything though, and [malware](https://securelist.com/sparkcat-stealer-in-app-store-and-google-play/115385) still slips through the cracks. From e9a7b9dbbdc63457c0ab45cf93607922753bece0 Mon Sep 17 00:00:00 2001 From: fria <138676274+friadev@users.noreply.github.com> Date: Sun, 9 Nov 2025 09:00:22 -0600 Subject: [PATCH 68/68] add optional app hardening --- blog/posts/ios-vs-android.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/blog/posts/ios-vs-android.md b/blog/posts/ios-vs-android.md index b723e2d0..e472b157 100644 --- a/blog/posts/ios-vs-android.md +++ b/blog/posts/ios-vs-android.md @@ -308,3 +308,7 @@ I hope Google will see app fingerprinting as a real problem and take steps to mi ## Optional App Hardening +While enforcing strong security is great, it's not always possible to force all apps to adhere to the best security practices. That's why providing developers optional security features they can enable is so beneficial; developers can get their apps ready for them before they become the default. For example, MTE is a new hardware security feature recently enabled in the stock OS on Google Pixels and on iPhones. If Apple and Google made it on by default, a lot of apps would constantly crash and it would ruin the user experience. Giving devs an opportunity to test it out and enable it optionally first allows them to get their app ready so they can seemlessly transition to the new default security after a while. + +### iOS +